Comparison Overview
Disney+ Hotstar

Disney+ Hotstar
Urmi Estate,, Mumbai, 400 013, IN
Last Update: 12/03/2026
Disney+ Hotstar is leading the way as the largest and smartest video platform in the country, reaching over 300+ million users today. We have set a number of world records along the way - including for the highest concurrent viewership at 59 million during the ICC Men's...

Rakuten
Rakuten Crimson House, Setagaya-ku, 158-0094, JP
Last Update: 07/10/2026
Rakuten Group, Inc. (TSE: 4755) is a global technology leader in services that empower individuals, communities, businesses and society. Founded in Tokyo in 1997 as an online marketplace, Rakuten has expanded to offer services in e-commerce, fintech, digital content and...
Compliance Ranges Comparison

Disney+ Hotstar







Rakuten






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Disney+ Hotstar in 2026.
Incidents vs Software Development Industry Avg (This Year)
Rakuten has 98.02% more incidents than the average of all companies with at least one recorded incident.
Incident History - Disney+ Hotstar (X = Date, Y = Severity)
Disney+ Hotstar cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Rakuten (X = Date, Y = Severity)
Rakuten cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Disney+ Hotstar

Rakuten
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.