cbcvebase.

Apache Thrift vulnerabilities

33 known vulnerabilities affecting apache/thrift.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH22MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2026-43871P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-43871 [HIGH] CWE-835 CVE-2026-43871: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PH Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41608P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-41608 [HIGH] CWE-409 CVE-2026-41608: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Pyth Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-48586P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-48586 [HIGH] CWE-409 CVE-2026-48586: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-58389P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-58389 [HIGH] CWE-770 CVE-2026-58389: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-49158P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-49158 [HIGH] CWE-409 CVE-2026-49158: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-45112P3HIGHCVSS 7.5≥ 0.19.0, < 0.24.02026-07-27
CVE-2026-45112 [HIGH] CWE-770 CVE-2026-45112: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-55968P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-55968 [HIGH] CWE-407 CVE-2026-55968: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41607P3MEDIUMCVSS 6.5fixed in 0.23.02026-04-28
CVE-2026-41607 [MEDIUM] CWE-125 CVE-2026-41607: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-55970P4MEDIUMCVSS 6.5fixed in 0.24.02026-07-27
CVE-2026-55970 [MEDIUM] CWE-126 CVE-2026-55970: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2015-3254P4MEDIUMCVSS 6.5≤ 0.9.22017-06-16
CVE-2015-3254 [MEDIUM] CWE-20 CVE-2015-3254: The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
nvd
CVE-2026-43868P4MEDIUMCVSS 5.3fixed in 0.23.02026-05-05
CVE-2026-43868 [MEDIUM] CVE-2026-43868: Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apac Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
ghsanvd
CVE-2026-41606P4MEDIUMCVSS 5.3fixed in 0.23.02026-04-28
CVE-2026-41606 [MEDIUM] CWE-674 CVE-2026-41606: Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.2 Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-66053P4MEDIUMCVSS 5.9fixed in 0.24.02026-07-27
CVE-2026-66053 [MEDIUM] CWE-297 CVE-2026-66053: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603
nvd
Apache Thrift vulnerabilities | cvebase