Apache Software Foundation Apache Thrift vulnerabilities
29 known vulnerabilities affecting apache_software_foundation/apache_thrift.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH20MEDIUM5
Vulnerabilities
Page 2 of 2
CVE-2026-58389P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-58389 [HIGH] CWE-770 CVE-2026-58389: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-55968P3HIGHCVSS 7.5fixed in 0.24.02026-07-27
CVE-2026-55968 [HIGH] CWE-407 CVE-2026-55968: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-41636P3HIGHCVSS 7.5fixed in 0.23.02026-04-28
CVE-2026-41636 [HIGH] CWE-674 CVE-2026-41636: Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Th
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2018-11798P3MEDIUMCVSS 6.5vApache Thrift 0.9.2 to 0.11.02019-01-07
CVE-2018-11798 [MEDIUM] CWE-538 CVE-2018-11798: The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
nvd
CVE-2026-41603P3HIGHCVSS 7.4fixed in 0.23.02026-04-28
CVE-2026-41603 [HIGH] CWE-297 CVE-2026-41603: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-41607P3MEDIUMCVSS 6.5fixed in 0.23.02026-04-28
CVE-2026-41607 [MEDIUM] CWE-125 CVE-2026-41607: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
CVE-2026-55970P3MEDIUMCVSS 6.5fixed in 0.24.02026-07-27
CVE-2026-55970 [MEDIUM] CWE-126 CVE-2026-55970: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
nvd
CVE-2026-66053P4MEDIUMCVSS 5.9fixed in 0.24.02026-07-27
CVE-2026-66053 [MEDIUM] CWE-297 CVE-2026-66053: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
nvd
CVE-2026-41606P4MEDIUMCVSS 5.3fixed in 0.23.02026-04-28
CVE-2026-41606 [MEDIUM] CWE-674 CVE-2026-41606: Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.2
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
nvd
← Previous2 / 2