Apache Thrift security advisories

Security information for Apache Thrift

Reporting

Do you want disclose a potential security issue for Apache Thrift? Send your report to the Apache Security Team.

You can read more about the security policy on:

Advisories

This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org

Erlang thrift_json_protocol reads a whole message with no size bound

CVE-2026-96990 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:00:25.502Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

nodejs web server: no error listener on an upgraded WebSocket connection

CVE-2026-96294 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:09:53.242Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Lua THttpTransport:_parseHeaders matches each header line with a backtracking pattern (quadratic)

CVE-2026-96292 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:11:30.594Z

Affected

  • Apache Thrift before 0.25.0

Description

Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

php --gen php:inlined struct readers (and TProtocol::skipBinary) have no recursion-depth guard

CVE-2026-96289 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:07:00.960Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Erlang generated struct reads have no recursion-depth guard (unbounded memory)

CVE-2026-96288 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:18:35.296Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Perl FramedTransport reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)

CVE-2026-96287 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:05:57.430Z

Affected

  • Apache Thrift before 0.25.0

Description

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Perl servers end serve() when serving one connection fails

CVE-2026-96286 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:04:24.079Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception vulnerability in Apache Thrift Perl bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Ruby SimpleServer ends serve() on any non-Transport/Protocol exception

CVE-2026-96277 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:03:22.302Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Lua TFramedTransport/THttpTransport re-slice the buffer on every read (quadratic)

CVE-2026-94658 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:02:20.074Z

Affected

  • Apache Thrift before 0.25.0

Description

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

javame TJsonProtocol/TJSONProtocol has no string size bound

CVE-2026-94657 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:01:35.174Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

rb TJsonProtocol/TJSONProtocol has no string size bound

CVE-2026-94656 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:00:46.391Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Lua TJsonProtocol string/number readers have no size bound and are quadratic

CVE-2026-94655 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:59:15.906Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Python TNonblockingServer busy-loops and stops selecting all fds after an 8192-byte-boundary frame

CVE-2026-94654 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:58:47.375Z

Affected

  • Apache Thrift before 0.25.0

Description

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)

CVE-2026-94653 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:56:33.859Z

Affected

  • Apache Thrift before 0.25.0

Description

Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

C++ TEvhttpServer leaks its RequestContext when the processor throws before calling back

CVE-2026-94652 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:54:39.118Z

Affected

  • Apache Thrift before 0.25.0

Description

Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Java TSaslNonblockingServer Computation.run orphans a connection on a pre-auth parse error

CVE-2026-94651 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:48:32.419Z

Affected

  • Apache Thrift before 0.25.0

Description

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)

CVE-2026-94650 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:49:35.651Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

dart TJsonProtocol/TJSONProtocol has no string size bound

CVE-2026-94648 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:52:47.045Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Node.js server.js ends the process on any per-connection error (+ two triggers)

CVE-2026-94646 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:57:22.883Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Node.js TJSONProtocol uses a peer-declared container size as an unbounded loop bound

CVE-2026-94645 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:51:36.420Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

PHP TJSONProtocol string/number readers have no size bound

CVE-2026-94644 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:53:33.571Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

PHP TSimpleServer exits the whole process on any non-transport exception

CVE-2026-94642 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:57:13.128Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Java TSaslNonblockingServer: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)

CVE-2026-94639 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T09:33:49.406Z

Affected

  • Apache Thrift before 0.25.0

Description

improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

PHP thrift_protocol C extension ignores the configured maxStringSize

CVE-2026-94638 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:49:41.453Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Go THeaderTransport does not bound the inflated size of a ZLIB frame

CVE-2026-94637 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:49:01.158Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Python TZlibTransport stops enforcing its decompressed-size limit once the limit is exactly used up

CVE-2026-94636 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:47:52.635Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Sylwester Lachiewicz (finder)

Lua TBinaryProtocol:readMessageBegin bypasses checkStringSize on the pre-versioned name

CVE-2026-94635 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T09:05:56.419Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

Python TJSONProtocol has a string length limit that is off by default

CVE-2026-94634 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:11:18.689Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

Dart TBinaryProtocol.readMessageBegin allocates from the pre-versioned name length

CVE-2026-94633 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:12:57.695Z

Affected

  • Apache Thrift before 0.25.0

Description

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

C++ THeaderTransport::untransform() leaks the zlib stream on the error path

CVE-2026-93926 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:14:57.912Z

Affected

  • Apache Thrift before 0.25.0

Description

Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • glit3h from ZeroVuln Labs (finder)

C++ THeaderTransport::writeVarint32() stack buffer overflow on a negative protocol id

CVE-2026-93925 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:16:09.141Z

Affected

  • Apache Thrift before 0.25.0

Description

Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • glit3h from ZeroVuln Labs (finder)

C++ WebSocket server transport does not read a full request length

CVE-2026-92834 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:45:22.654Z

Affected

  • Apache Thrift before 0.25.0

Description

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

PHP thrift_protocol accelerator: zero-byte container elements

CVE-2026-91137 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:18:34.190Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • glit3h from ZeroVuln Labs (finder)

C++ THeaderTransport::transform() heap buffer overflow (write direction)

CVE-2026-91135 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:28:47.666Z

Affected

  • Apache Thrift before 0.25.0

Description

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.

When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • glit3h from ZeroVuln Labs (finder)

An exception escaping a libevent callback stops the D library’s non-blocking server, allowing an unauthenticated remote attacker to deny service

CVE-2026-90440 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:44:09.882Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

PHP thrift_protocol accelerator dereferences a missing container-element spec

CVE-2026-87117 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:43:10.120Z

Affected

  • Apache Thrift before 0.25.0

Description

NULL pointer dereference vulnerability in Apache Thrift PHP bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

A truncated HTTP request stops the D library’s server, allowing an unauthenticated remote attacker to deny service

CVE-2026-86537 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:40:50.109Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

A map key from the wire can replace a decoded object’s prototype in generated JavaScript

CVE-2026-86536 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:39:59.296Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue.

References

Credits

  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

A JSON member name can stall the Node server’s event loop indefinitely

CVE-2026-86535 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:38:14.489Z

Affected

  • Apache Thrift before 0.25.0

Description

Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)

CVE-2026-85494 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:42:42.564Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Ho1aAs xxy010605@gmail.com for py, rb, erl, lua, dart, javame, d bindings (finder)
  • Perl/PHP bindings were found by the Apache Thrift project’s own cross-language sweep (finder)
  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)

CVE-2026-85493 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:45:55.375Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

c_glib TZlibTransport reports a full read after a premature stream end

CVE-2026-85483 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T10:46:53.193Z

Affected

  • Apache Thrift before 0.25.0

Description

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Ho1aAs xxy010605@gmail.com (finder)
  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

c_glib read_all spins when the underlying read returns 0

CVE-2026-85476 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:12:37.604Z

Affected

  • Apache Thrift before 0.25.0

Description

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match

CVE-2026-85088 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:37:12.940Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.

Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host
name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than
a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check.

RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a
Common Name for another is therefore accepted for a connection to the second name.

Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host
name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure.

This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.

References

Credits

  • The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

Python ≥3.12 host-name check silently becomes a no-op

CVE-2026-85087 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:35:42.674Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

Perl TLS client disables certificate verification by default

CVE-2026-85086 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:33:58.761Z

Affected

  • Apache Thrift before 0.25.0

Description

Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift (finder)

WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)

CVE-2026-83745 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:16:12.360Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift  nodejs and D lang bindings.

Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.

This issue affects Apache Thrift before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Ho1aAs xxy010605@gmail.com for Node.js (finder)
  • Apache Thrift Developers for D language (finder)

TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)

CVE-2026-83663 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:18:15.518Z

Affected

  • Apache Thrift before 0.25.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift go bindings.

Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Ho1aAs xxy010605@gmail.com for TFramedTransport (finder)
  • Apache Thrift Developers for THeaderTransport (finder)

C++ THttpTransport grows its line buffer without bound

CVE-2026-83632 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:22:22.014Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Ho1aAs xxy010605@gmail.com (finder)
  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)

Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process

CVE-2026-82459 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:32:28.180Z

Affected

  • Apache Thrift before 0.25.0

Description

Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift (finder)

Container element count not bounded by the bytes available

CVE-2026-82458 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:30:13.881Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • denyspakizh-tob (Trail of Bits) for the Go bindings (finder)
  • David Walker (Workiva, Inc) independent co-discoverer (finder)
  • Ho1aAs xxy010605@gmail.com independent rediscovery (Go THeaderTransport transform count) (finder)
  • Apache Thrift Developers (finder)

c_glib multiplexed processor crashes on a message it cannot route

CVE-2026-66859 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:23:46.689Z

Affected

  • Apache Thrift before 0.25.0

Description

NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)

CVE-2026-66858 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:27:29.550Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Claude (Anthropic Research) (finder)
  • Arthur Chan, Ada Logics (analyst)
  • Apache Thrift Developers (finder)

PHP accelerator sizes a stack buffer from a wire-controlled string length

CVE-2026-66837 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:29:07.376Z

Affected

  • Apache Thrift before 0.25.0

Description

Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

Buffered transport reads are not accounted against MaxMessageSize

CVE-2026-66331 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:32:44.751Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

c_glib read_message_begin leaves output parameters unset for non-versioned messages

CVE-2026-66081 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:33:12.312Z

Affected

  • Apache Thrift before 0.25.0

Description

Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)

CVE-2026-66055 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:49:39.024Z

Affected

  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0
  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Bin Luo, University of Electronic Science and Technology of China (UESTC) (C++) (finder)
  • Apache Thrift Developers (Java/Go/netstd/Python/Delphi) (finder)

C++ THeaderTransport does not enforce configured maxFrameSize

CVE-2026-66054 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:51:20.441Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Bin Luo, University of Electronic Science and Technology of China (UESTC) (finder)

Python TSSLSocket Hostname Matcher Import

CVE-2026-66053 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:18:43.366Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

References

Credits

Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count

CVE-2026-63772 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:52:05.727Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

  • Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski (finder)

Java TSaslTransport post-auth data-frame missing size limit

CVE-2026-61374 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T12:52:58.028Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation

CVE-2026-61373 [CVE] [CVE json] [OSV json]

Last updated: 2026-10-02T11:07:26.862Z

Affected

  • Apache Thrift before 0.25.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

References

Credits

C++ THeaderTransport::readString() info-header length bounds bypass

CVE-2026-58662 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:17:20.407Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

Rust binary protocol non-strict path missing string size limit

CVE-2026-58389 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:14:25.617Z

Affected

  • Apache Thrift before 0.24.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

c_glib heap out-of-bounds read in transport leftover-bytes path

CVE-2026-58023 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:12:35.855Z

Affected

  • Apache Thrift before 0.24.0

Description

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

CVE-2026-55971 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:11:18.790Z

Affected

  • Apache Thrift before 0.24.0

Description

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)

C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()

CVE-2026-55970 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:09:36.113Z

Affected

  • Apache Thrift before 0.24.0

Description

Buffer Over-read vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)

integer overflow in TProtocol::checkReadBytesAvailable()

CVE-2026-55969 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:07:43.565Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)
  • Javid Khan (finder)
  • Apache Thrift Developers (finder)

Node.js quadratic-time DoS in server receive transports

CVE-2026-55968 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:06:12.486Z

Affected

  • Apache Thrift before 0.24.0

Description

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Song Jihoon (finder)

Ruby THeaderTransport ZLIB Decompression Bomb

CVE-2026-49158 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:05:01.307Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

TZlibTransport Decompression Size Limit

CVE-2026-48586 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:02:50.181Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

CVE-2026-48145 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:59:40.690Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

c_glib TLS Client Missing Hostname Verification

CVE-2026-48144 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:58:24.417Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Unbounded Read Leading to Denial of Service

CVE-2026-45112 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:57:25.527Z

Affected

  • Apache Thrift from 0.19.0 before 0.24.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.

This issue affects Apache Thrift: from 0.19.0 before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • IcySun & Yashon (finder)

TCompactProtocol varint byte-count limit

CVE-2026-43871 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:56:06.868Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Loop with Unreachable Exit Condition (‘Infinite Loop’) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

Node.js web_server.js multi-vulnerability

CVE-2026-43870 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-01T15:14:33.689Z

Affected

  • Apache Thrift before 0.23.0

Description

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

TSSLTransportFactory.java hostname verification

CVE-2026-43869 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-01T15:15:50.815Z

Affected

  • Apache Thrift before 0.23.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

Rust implementation vulnerable to CVE-2020-13949 pattern

CVE-2026-43868 [CVE] [CVE json] [OSV json]

Last updated: 2026-05-05T07:49:46.378Z

Affected

  • Apache Thrift before 0.23.0

Description

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Node.js skip() recursion

CVE-2026-41636 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-15T20:56:45.279Z

Affected

  • Apache Thrift before 0.23.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Sion Park (L3G4CY Security Research) (finder)
  • Yu Bao – yubao@paypal.com (finder)

Unbounded Zlib Decompression in Python THeaderTransport

CVE-2026-41608 [CVE] [CVE json] [OSV json]

Last updated: 2026-09-14T21:15:42.689Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

C++ JSON OOB read

CVE-2026-41607 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:21:46.727Z

Affected

  • Apache Thrift before 0.23.0

Description

Out-of-bounds Read vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

c_glib dispatch stack overflow

CVE-2026-41606 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:21:09.783Z

Affected

  • Apache Thrift before 0.23.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Swift Compact Protocol integer overflow

CVE-2026-41605 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:20:43.166Z

Affected

  • Apache Thrift before 0.23.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Swift Range crash in skip()

CVE-2026-41604 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:20:12.306Z

Affected

  • Apache Thrift before 0.23.0

Description

Out-of-bounds Read vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Go TFramedTransport uint32 overflow

CVE-2026-41602 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:19:05.731Z

Affected

  • Apache Thrift before 0.23.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • 김범수 (finder)

Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

CVE-2025-48431 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:11:42.895Z

Affected

  • Apache Thrift before 0.23.0

Description

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

References

Credits

  • Hasnain Lakhani (finder)
  • Hasnain Lakhani (remediation developer)