VendorsApachethriftany version
Vulnerabilities

Apache Software Foundation Thrift any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2026-55971
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Published 2026-07-27 · Analyzed
9.8EPSS 0.006
CVE-2026-41607
Apache Thrift: C++ JSON OOB read
Published 2026-04-28 · Modified
9.1EPSS 0.009
CVE-2026-58023
Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
Published 2026-07-27 · Analyzed
9.1EPSS 0.006
CVE-2026-58662
Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Published 2026-07-27 · Analyzed
9.1EPSS 0.006
CVE-2026-48144
Apache Thrift: c_glib TLS Client Missing Hostname Verification
Published 2026-07-27 · Analyzed
9.1EPSS 0.003
CVE-2016-5397
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Published 2018-02-12 · Modified
9.0EPSS 0.069
CVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Published 2026-07-27 · Analyzed
8.7EPSS 0.006
CVE-2026-48586
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
Published 2026-07-27 · Analyzed
8.7EPSS 0.006
CVE-2026-55968
Apache Thrift: Node.js quadratic-time DoS in server receive transports
Published 2026-07-27 · Analyzed
8.7EPSS 0.006
CVE-2026-58389
Apache Thrift: Rust binary protocol non-strict path missing string size limit
Published 2026-07-27 · Analyzed
8.7EPSS 0.006
CVE-2026-43871
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Published 2026-07-27 · Analyzed
8.7EPSS 0.006
CVE-2026-41636
Apache Thrift: Node.js skip() recursion
Published 2026-04-28 · Analyzed
8.7EPSS 0.005
CVE-2026-41604
Apache Thrift: Swift Range crash in skip()
Published 2026-04-28 · Modified
8.2EPSS 0.009
CVE-2026-48145
Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Published 2026-07-27 · Analyzed
8.2EPSS 0.003
CVE-2019-0205
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Published 2019-10-28 · Modified
7.8EPSS 0.092
CVE-2026-41605
Apache Thrift: Swift Compact Protocol integer overflow
Published 2026-04-28 · Modified
7.7EPSS 0.009
CVE-2018-1320
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
Published 2019-01-07 · Modified
7.5EPSS 0.082
CVE-2020-13949
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Published 2021-02-12 · Modified
7.5EPSS 0.068
CVE-2019-0210
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Published 2019-10-28 · Modified
7.5EPSS 0.064
CVE-2026-41602
Apache Thrift: Go TFramedTransport uint32 overflow
Published 2026-04-28 · Modified
7.5EPSS 0.012
CVE-2026-41606
Apache Thrift: c_glib dispatch stack overflow
Published 2026-04-28 · Modified
7.5EPSS 0.011
CVE-2025-48431
Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
Published 2026-04-28 · Modified
7.5EPSS 0.011
CVE-2026-45112
Apache Thrift: Unbounded Read Leading to Denial of Service
Published 2026-07-27 · Analyzed
7.5EPSS 0.011
CVE-2026-43868
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
Published 2026-05-05 · Modified
7.5EPSS 0.007
CVE-2026-49158
Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
Published 2026-07-27 · Analyzed
7.5EPSS 0.006
CVE-2026-41608
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Published 2026-07-27 · Modified
7.5EPSS 0.006
CVE-2026-43869
Apache Thrift: TSSLTransportFactory.java hostname verification
Published 2026-05-05 · Modified
7.3EPSS 0.006
CVE-2026-43870
Apache Thrift: Node.js web_server.js multi-vulnerability
Published 2026-05-05 · Analyzed
7.3EPSS 0.004
CVE-2026-55970
Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Published 2026-07-27 · Analyzed
6.9EPSS 0.005
CVE-2015-3254
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
Published 2017-06-16 · Modified
6.5EPSS 0.053
CVE-2018-11798
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
Published 2019-01-07 · Modified
6.5EPSS 0.049
CVE-2026-66053
Apache Thrift: Python TSSLSocket Hostname Matcher Import
Published 2026-07-27 · Analyzed
5.9EPSS 0.002