Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ltshfwjt

#16717of 56,330
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-66517
9.8
2026-07-30
Apache · Apache Kyuubi · CVE-2026-52680
**Name of the Vulnerable Software and Affected Versions** Apache Kyuubi versions 1.7.0 through 1.11.1 **Description** Improper handling of REST batch multipart uploads allows a remote attacker to use path traversal sequences in the client-supplied filename. This can lead to the server writing controlled content outside the intended upload directory, depending on filesystem permissions, via the REST batch upload endpoint. **Recommendations** Upgrade to version 1.12.0.
PT-2026-64883
7.5
2026-07-27
Apache · Apache Thrift · CVE-2026-49158
**Name of the Vulnerable Software and Affected Versions** Apache Thrift versions prior to 0.24.0 **Description** Improper handling of highly compressed data, known as data amplification, exists in the Apache Thrift Ruby bindings. This issue occurs during ZLIB decompression within the `THeaderTransport` component, which could lead to a decompression bomb, where a small compressed input expands to a massive size in memory. **Recommendations** Upgrade to version 0.24.0.