Apache Thrift vulnerabilities
33 known vulnerabilities affecting apache/thrift.
Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH22MEDIUM7
Vulnerabilities
Page 1 of 2
CVE-2016-5397P3HIGHCVSS 8.8≤ 0.9.32018-02-12
CVE-2016-5397 [HIGH] CWE-77 CVE-2016-5397: The Apache Thrift Go client library exposed the potential during code generation for command injecti
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
nvd
CVE-2026-55971P3CRITICALCVSS 9.8fixed in 0.24.02026-07-27
CVE-2026-55971 [CRITICAL] CWE-122 CVE-2026-55971: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache T
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2019-0205P3HIGHCVSS 7.5≤ 0.12.02019-10-29
CVE-2019-0205 [HIGH] CWE-835 CVE-2019-0205: In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
nvd
CVE-2018-1320P3HIGHCVSS 7.5≥ 0.5.0, ≤ 0.11.02019-01-07
CVE-2018-1320 [HIGH] CWE-295 CVE-2018-1320: Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComple
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
nvd
CVE-2026-41604P3HIGHCVSS 8.2fixed in 0.23.02026-04-28
CVE-2026-41604 [HIGH] CWE-125 CVE-2026-41604: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-48144P3CRITICALCVSS 9.1fixed in 0.24.02026-07-27
CVE-2026-48144 [CRITICAL] CWE-297 CVE-2026-48144: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-58662P3CRITICALCVSS 9.1fixed in 0.24.02026-07-27
CVE-2026-58662 [CRITICAL] CWE-125 CVE-2026-58662: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrif
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-58023P3CRITICALCVSS 9.1fixed in 0.24.02026-07-27
CVE-2026-58023 [CRITICAL] CWE-125 CVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2025-48431P3HIGHCVSS 7.5fixed in 0.23.02026-04-28
CVE-2025-48431 [HIGH] CWE-762 CVE-2025-48431: Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" err
nvd
CVE-2026-41603P3HIGHCVSS 7.4fixed in 0.23.02026-04-28
CVE-2026-41603 [HIGH] CWE-297 CVE-2026-41603: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-43870P3HIGHCVSS 7.3fixed in 0.23.02026-05-05
CVE-2026-43870 [HIGH] CWE-22 CVE-2026-43870: Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversa
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to v
ghsanvd
CVE-2019-0210P3HIGHCVSS 7.5≥ 0.9.3, ≤ 0.12.02019-10-29
CVE-2019-0210 [HIGH] CWE-125 CVE-2019-0210: In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProto
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
nvd
CVE-2020-13949P3HIGHCVSS 7.5≥ 0.9.3, ≤ 0.13.02021-02-12
CVE-2020-13949 [HIGH] CWE-400 CVE-2020-13949: In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
nvd
CVE-2026-41605P3HIGHCVSS 7.3fixed in 0.23.02026-04-28
CVE-2026-41605 [HIGH] CWE-190 CVE-2026-41605: Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: be
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-43869P3HIGHCVSS 7.3fixed in 0.23.02026-05-05
CVE-2026-43869 [HIGH] CWE-297 CVE-2026-43869: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-41602P3HIGHCVSS 7.5fixed in 0.23.02026-04-28
CVE-2026-41602 [HIGH] CWE-190 CVE-2026-41602: Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implement
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-48145P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-48145 [HIGH] CWE-297 CVE-2026-48145: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41636P3HIGHCVSS 7.5fixed in 0.23.02026-04-28
CVE-2026-41636 [HIGH] CWE-674 CVE-2026-41636: Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Th
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ghsanvd
CVE-2018-11798P3MEDIUMCVSS 6.5≥ 0.9.2, ≤ 0.11.02019-01-07
CVE-2018-11798 [MEDIUM] CWE-538 CVE-2018-11798: The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
nvd
CVE-2026-55969P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-55969 [HIGH] CWE-190 CVE-2026-55969: Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Ha
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
1 / 2Next →