cbcvebase.

Apache Software Foundation Apache Thrift vulnerabilities

29 known vulnerabilities affecting apache_software_foundation/apache_thrift.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH20MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2026-58389P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-58389 [HIGH] CWE-770 CVE-2026-58389: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-55968P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-55968 [HIGH] CWE-407 CVE-2026-55968: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41636P3HIGHCVSS 7.5fixed in 0.23.02026-04-28
CVE-2026-41636 [HIGH] CWE-674 CVE-2026-41636: Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Th Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2018-11798P3MEDIUMCVSS 6.5vApache Thrift 0.9.2 to 0.11.02019-01-07
CVE-2018-11798 [MEDIUM] CWE-538 CVE-2018-11798: The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
nvd
CVE-2026-41603P3HIGHCVSS 7.4fixed in 0.23.02026-04-28
CVE-2026-41603 [HIGH] CWE-297 CVE-2026-41603: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-41607P3MEDIUMCVSS 6.5fixed in 0.23.02026-04-28
CVE-2026-41607 [MEDIUM] CWE-125 CVE-2026-41607: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-55970P3MEDIUMCVSS 6.5fixed in 0.24.02026-07-27
CVE-2026-55970 [MEDIUM] CWE-126 CVE-2026-55970: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-66053P4MEDIUMCVSS 5.9fixed in 0.24.02026-07-27
CVE-2026-66053 [MEDIUM] CWE-297 CVE-2026-66053: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603
nvd
CVE-2026-41606P4MEDIUMCVSS 5.3fixed in 0.23.02026-04-28
CVE-2026-41606 [MEDIUM] CWE-674 CVE-2026-41606: Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.2 Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
Apache Software Foundation Apache Thrift vulnerabilities | cvebase