Apache Thrift

Apache · 91 CVEs

CVE-2026-66054
MEDIUM

Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize

Oct 2, 2026

CVE-2026-61374
HIGH

Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit

Oct 2, 2026

CVE-2026-63772
HIGH

Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count

Oct 2, 2026

CVE-2026-66055
HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a singl…

Oct 2, 2026

CVE-2026-66081
HIGH

Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages

Oct 2, 2026

CVE-2026-66331
MEDIUM

Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize

Oct 2, 2026

CVE-2026-66837
HIGH

Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length

Oct 2, 2026

CVE-2026-66858
HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the rec…

Oct 2, 2026

CVE-2026-66859
HIGH

Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route

Oct 2, 2026

CVE-2026-83632
CRITICAL

Apache Thrift: C++ THttpTransport grows its line buffer without bound

Oct 2, 2026

CVE-2026-83663
HIGH

Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)

Oct 2, 2026

CVE-2026-83745
HIGH

Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the by…

Oct 2, 2026

CVE-2026-85476
HIGH

Apache Thrift: c_glib `read_all` spins when the underlying read returns 0

Oct 2, 2026

CVE-2026-96289
HIGH

Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard

Oct 2, 2026

CVE-2026-96287
HIGH

Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadrati…

Oct 2, 2026

CVE-2026-96286
HIGH

Apache Thrift: Perl servers end `serve()` when serving one connection fails

Oct 2, 2026

CVE-2026-96277
HIGH

Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception

Oct 2, 2026

CVE-2026-94658
HIGH

Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)

Oct 2, 2026

CVE-2026-94657
HIGH

Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound

Oct 2, 2026

CVE-2026-94656
HIGH

Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound

Oct 2, 2026

CVE-2026-94655
HIGH

Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic

Oct 2, 2026

CVE-2026-94654
HIGH

Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame

Oct 2, 2026

CVE-2026-94653
HIGH

Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)

Oct 2, 2026

CVE-2026-94652
MEDIUM

Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back

Oct 2, 2026

CVE-2026-94648
HIGH

Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound

Oct 2, 2026

Showing 1 to 25 of 91 CVEs