These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for a crash or resource exhaustion through abusive HTTP/2 frami [truncated]
The CVE-2026-22068 record indicates a Regular Expression without Anchors vulnerability in Apache Traffic Server versions from 10.0.X through 10.1.3 and from 9.0.X through 9.2.14. This issue allows attackers to potentially bypass security checks, leading to security risks. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. The CVSS score is 6.9 and the severity is MEDIUM. [truncated]
CVE-2026-66713 is a deserialization of untrusted data vulnerability in the Tribes-based clustering component of Apache Axis2/Java. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code via a crafted serialized Java object when Tribes clustering is enabled. The issue is resolved in version 2.0.1 by removing the clustering feature entirely. Affected deployments should be ide [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then. This Improper Authorization vulnerability in Apache ActiveMQ allows an authenticated low-privilege user to bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated comp [truncated]
CVE-2026-59878 is an Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, and Apache ActiveMQ All. A remote unauthenticated peer can trigger denial-of-service behavior by sending a frame size value, causing NIO threads to die and potentially leading to exhaustion of the NIO thread pool. This issue affects versions before 5.19.9 and from 6.0.0 before 6.2.8 for all three product [truncated]
CVE-2026-66391 is a Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. The issue affects Apache Wicket versions from 9.0.0 through 9.23.0 and from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The CVE record was published on 20 [truncated]
CVE-2026-66390 is a Cross-site Scripting vulnerability in Apache Wicket. The issue affects Apache Wicket versions from 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue. This vulnerability has a CVSS score of 6.1, indicating a medium severity level. The vulnerability occurs when user input is not properly sanitized, allowing an attac [truncated]
CVE-2026-66053 is an Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. The issue affects Apache Thrift before version 0.24.0, potentially impacting users of affected versions. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This CVE replaces CVE-2026-41603. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity.
CVE-2026-58662 is an Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability has a CVSS score of 8.7 and is classified as HIGH. The CVE record was published on 2026-07-27T12:16:46.807Z.
CVE-2026-58389 is an Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. The issue affects Apache Thrift versions before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability could potentially lead to resource exhaustion or other issues due to the lack of limits or throttling in the allocation of resources. An e [truncated]
Apache Thrift c_glib bindings have an Out-of-bounds Read vulnerability. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability can be fixed by upgrading to version 0.24.0 or later. It is recommended that users of Apache Thrift c_glib bindings bef [truncated]
CVE-2026-55971 is a Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. Affected product deployments should be identified and owners assigned for follow-up.
CVE-2026-55970 is a Buffer Over-read vulnerability in Apache Thrift C++ bindings. The issue affects Apache Thrift versions before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability can be exploited by attackers to read sensitive data from memory. Affected systems and applications should be reviewed and updated.
A vulnerability was discovered in Apache Thrift Node.js bindings, classified as Inefficient Algorithmic Complexity and Allocation of Resources Without Limits or Throttling. This issue affects Apache Thrift versions before 0.24.0. Users are advised to upgrade to version 0.24.0, which addresses the vulnerability. The vulnerability can potentially lead to performance issues or crashes if exploited. It is ess [truncated]
CVE-2026-49158 is an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability can lead to a denial of service (DoS) attack. Affected users should review and update systems to ensure security. The vulnerabi [truncated]
CVE-2026-48586 is an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability affecting Apache Thrift C++, Java, Python, Go, D, C/GLib bindings before version 0.24.0. This issue allows for potential data amplification attacks. Users are advised to upgrade to version 0.24.0 to address the issue. The CVSS score for this vulnerability is 8.7, indicating a high severity level. Affected u [truncated]
CVE-2026-48145 is an Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability can be exploited by attackers to compromise the security of affected systems. Affected users should review and update their systems to prev [truncated]
CVE-2026-48144 is an Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. The issue affects Apache Thrift before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability can be exploited by attackers to compromise the security of affected systems. It is crucial for users of Apache Thrift c_glib bindings before ve [truncated]
CVE-2026-45112 is an Allocation of Resources Without Limits or Throttling vulnerability affecting Apache Thrift Java bindings from version 0.19.0 up to but not including 0.24.0. This issue has a CVSS score of 6.9 and is considered medium severity. Users are advised to upgrade to version 0.24.0 to address the issue. The vulnerability, classified as CWE-770, allows for an allocation of resources without lim [truncated]
CVE-2026-43871 is an Infinite Loop vulnerability in Apache Thrift Python, Go, PHP and Java bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. The vulnerability has a CVSS score of 8.7 and a severity of HIGH. Affected users should review and update affected systems. The CVE record was published on 2026-07-27T12:16:44.413Z an [truncated]
CVE-2026-41608 is an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. The issue affects Apache Thrift before version 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This vulnerability can lead to data amplification attacks, and users of Apache Thrift Python bindings should be aware of this vulnerability and [truncated]
Apache HBase has a Missing Authorization vulnerability in its thrift and rest delegation service, allowing users to fetch rows from scanners opened by other users and close scanners belonging to other users. This issue affects Apache HBase versions from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, and through 2.4.*. Users are recommended to upgrade to version 3. [truncated]
CVE-2026-66144 is a high-severity denial of service vulnerability in Apache Neethi. Although remote policy references are not retrieved during policy normalization, manually retrieving them via the API can cause a denial of service attack if a huge policy is retrieved. The issue arises from the lack of a default maximum size on data read from remote policy references. Users are recommended to upgrade to v [truncated]
CVE-2026-45815 is a Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response may trigger assert in ATT parser. The severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue. The vulnerability can be miti [truncated]
The CVE-2026-45813 vulnerability is an out-of-bounds write and integer underflow issue in the Apache NimBLE BASS service. This vulnerability can be triggered by nearby devices over Bluetooth connection, but pairing is required prior to accessing the BASS service. The issue affects Apache NimBLE through version 1.9.0 and is fixed in version 1.10.0. The vulnerability has a CVSS score of 8.8 and is classifie [truncated]
CVE-2026-45811 is a Buffer Copy without Checking Size of Input vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. This issue affects Apache NimBLE through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue. The vulnerability requires either a mis [truncated]
Apache OpenNLP is vulnerable to arbitrary class instantiation via XML feature generator descriptor and format name, affecting versions before 2.5.10 and before 3.0.0-M5. The vulnerability allows an attacker to load a class by its fully-qualified name via Class.forName() and invoke its no-arg constructor without prior validation. This requires a class with attacker-useful side effects in its static initial [truncated]
CVE-2026-60080 is a Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue. The vulnerability has a high impact and users should take immediate action to upgrade.
Apache MINA SSHD, a Java library for client-side and server-side SSH, contains an improper input validation vulnerability in the sshd-git component. This vulnerability allows an authenticated SSH client to execute arbitrary JGit commands on the server, potentially leading to file writes. The issue is fixed in Apache MINA SSHD versions 2.19.0 and 3.0.0-M5. The vulnerability has a CVSS score of 5.4 and a se [truncated]
The CVE record for CVE-2026-56624 was published on 2026-07-20T21:16:49.070Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Apache MINA SSHD server-side implementation, specifically related to improper certificate validation during user authentication. The vulnerability could allow users with certain certificates to execute commands beyond w [truncated]