From Our Security Partners
CVE-2026-41605 Apache Thrift: Swift Compact Protocol integer overflow
Information published.
CVE-2026-41603 Apache Thrift: Java TSSLTransportFactory hostname verification
Information published.
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
Information published.
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API
Information published.
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload
Information published.
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
Information published.
CVE-2026-39817 Invoking “go tool pack” does not sanitize output paths in cmd/go
Information published.