Apache Software Foundation Apache Thrift vulnerabilities
29 known vulnerabilities affecting apache_software_foundation/apache_thrift.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH20MEDIUM5
Vulnerabilities
Page 2 of 2
CVE-2026-48586P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-48586 [HIGH] CWE-409 CVE-2026-48586: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++,
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-58389P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-58389 [HIGH] CWE-770 CVE-2026-58389: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-49158P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-49158 [HIGH] CWE-409 CVE-2026-49158: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-45112P3HIGHCVSS 7.5≥ 0.19.0, < 0.24.02026-07-27
CVE-2026-45112 [HIGH] CWE-770 CVE-2026-45112: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-55968P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-55968 [HIGH] CWE-407 CVE-2026-55968: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41607P3MEDIUMCVSS 6.5fixed in 0.23.02026-04-28
CVE-2026-41607 [MEDIUM] CWE-125 CVE-2026-41607: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-55970P4MEDIUMCVSS 6.5fixed in 0.24.02026-07-27
CVE-2026-55970 [MEDIUM] CWE-126 CVE-2026-55970: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41606P4MEDIUMCVSS 5.3fixed in 0.23.02026-04-28
CVE-2026-41606 [MEDIUM] CWE-674 CVE-2026-41606: Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.2
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-66053P4MEDIUMCVSS 5.9fixed in 0.24.02026-07-27
CVE-2026-66053 [MEDIUM] CWE-297 CVE-2026-66053: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
nvd
← Previous2 / 2