[Git][security-tracker-team/security-tracker][master] thrift fixed in experimental
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Aug 8 19:03:39 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
966a0d23 by Moritz Muehlenhoff at 2026-08-08T20:03:11+02:00
thrift fixed in experimental
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9521,9 +9521,11 @@ CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C
CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in Roskus Pro ...)
NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bounds Read ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed> (unimportant)
NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
NOTE: rust bindings not built in Debian package
@@ -9536,6 +9538,7 @@ CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when recon
NOTE: Fixed by: https://github.com/erlang/otp/commit/241d43703989fec4b6bf637beaeb366d92dcc4c2 (OTP-28.5.0.4)
NOTE: Fixed by: https://github.com/erlang/otp/commit/7db64720177961e04545681480d691c4be81c54d (OTP-29.0.4)
CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
@@ -9547,16 +9550,20 @@ CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information disc
CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which could al ...)
NOT-FOR-US: HCL
CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
[trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7
CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed> (unimportant)
NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
NOTE: nodejs bindings not built in Debian package
@@ -9616,17 +9623,21 @@ CVE-2026-51244
CVE-2026-51235
REJECTED
CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed> (unimportant)
NOTE: https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7
NOTE: ruby bindings not built in Debian package
CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
[trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h
CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
CVE-2026-48052 (Papra is a minimalistic document management and archiving platform. Pr ...)
@@ -9650,9 +9661,11 @@ CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modi
NOTE: https://github.com/postcss/postcss/commit/94484cae6d4308167939f2ac888d166bd80dff01 (8.5.12)
NOTE: https://github.com/postcss/postcss/commit/85c4d7dab830be366f8a96047f9e5b7944e101d8 (8.5.12)
CVE-2026-45112 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc
CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
@@ -9662,6 +9675,7 @@ CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erl
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-42792
NOTE: Fixed by; https://github.com/erlang/otp/commit/865d203e4a6a8f44179eced9e1428f9259e4a3bb (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+ [experimental] - thrift 0.24.0-1
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/966a0d23b7766eb4fbd1561417aeef5f6089474f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/966a0d23b7766eb4fbd1561417aeef5f6089474f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/e2f39f5e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list