Apache Thrift
Apache · 91 CVEs
Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize
Oct 2, 2026
Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit
Oct 2, 2026
Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count
Oct 2, 2026
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a singl…
Oct 2, 2026
Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages
Oct 2, 2026
Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
Oct 2, 2026
Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length
Oct 2, 2026
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the rec…
Oct 2, 2026
Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
Oct 2, 2026
Apache Thrift: C++ THttpTransport grows its line buffer without bound
Oct 2, 2026
Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)
Oct 2, 2026
Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the by…
Oct 2, 2026
Apache Thrift: c_glib `read_all` spins when the underlying read returns 0
Oct 2, 2026
Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard
Oct 2, 2026
Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadrati…
Oct 2, 2026
Apache Thrift: Perl servers end `serve()` when serving one connection fails
Oct 2, 2026
Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception
Oct 2, 2026
Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic)
Oct 2, 2026
Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound
Oct 2, 2026
Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound
Oct 2, 2026
Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic
Oct 2, 2026
Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame
Oct 2, 2026
Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)
Oct 2, 2026
Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back
Oct 2, 2026
Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
Oct 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-66054 | Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize | MEDIUM | 0.43% | Oct 2, 2026 |
| CVE-2026-61374 | Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit | HIGH | 0.24% | Oct 2, 2026 |
| CVE-2026-63772 | Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-66055 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the confi… | HIGH | 0.26% | Oct 2, 2026 |
| CVE-2026-66081 | Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-66331 | Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize | MEDIUM | 0.43% | Oct 2, 2026 |
| CVE-2026-66837 | Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length | HIGH | 0.29% | Oct 2, 2026 |
| CVE-2026-66858 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, P… | HIGH | 0.26% | Oct 2, 2026 |
| CVE-2026-66859 | Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-83632 | Apache Thrift: C++ THttpTransport grows its line buffer without bound | CRITICAL | 0.38% | Oct 2, 2026 |
| CVE-2026-83663 | Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go) | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-83745 | Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D) | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-85476 | Apache Thrift: c_glib `read_all` spins when the underlying read returns 0 | HIGH | 0.41% | Oct 2, 2026 |
| CVE-2026-96289 | Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-96287 | Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic) | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-96286 | Apache Thrift: Perl servers end `serve()` when serving one connection fails | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-96277 | Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94658 | Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic) | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94657 | Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94656 | Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94655 | Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94654 | Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame | HIGH | 0.41% | Oct 2, 2026 |
| CVE-2026-94653 | Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic) | HIGH | 0.43% | Oct 2, 2026 |
| CVE-2026-94652 | Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back | MEDIUM | 0.43% | Oct 2, 2026 |
| CVE-2026-94648 | Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound | HIGH | 0.43% | Oct 2, 2026 |
Showing 1 to 25 of 91 CVEs