Apache Thrift security advisories

Security information for Apache Thrift

Reporting

Do you want disclose a potential security issue for Apache Thrift? Send your report to the Apache Security Team.

You can read more about the security policy on:

Advisories

This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org

Python TSSLSocket Hostname Matcher Import

CVE-2026-66053 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:18:43.366Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

References

Credits

C++ THeaderTransport::readString() info-header length bounds bypass

CVE-2026-58662 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:17:20.407Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

Rust binary protocol non-strict path missing string size limit

CVE-2026-58389 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:14:25.617Z

Affected

  • Apache Thrift before 0.24.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

c_glib heap out-of-bounds read in transport leftover-bytes path

CVE-2026-58023 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:12:35.855Z

Affected

  • Apache Thrift before 0.24.0

Description

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

CVE-2026-55971 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:11:18.790Z

Affected

  • Apache Thrift before 0.24.0

Description

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)

C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()

CVE-2026-55970 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:09:36.113Z

Affected

  • Apache Thrift before 0.24.0

Description

Buffer Over-read vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)

integer overflow in TProtocol::checkReadBytesAvailable()

CVE-2026-55969 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:07:43.565Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Ghaith Abdulreda (finder)
  • Javid Khan (finder)
  • Apache Thrift Developers (finder)

Node.js quadratic-time DoS in server receive transports

CVE-2026-55968 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:06:12.486Z

Affected

  • Apache Thrift before 0.24.0

Description

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • Song Jihoon (finder)

Ruby THeaderTransport ZLIB Decompression Bomb

CVE-2026-49158 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:05:01.307Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

TZlibTransport Decompression Size Limit

CVE-2026-48586 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T11:02:50.181Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

CVE-2026-48145 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:59:40.690Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

c_glib TLS Client Missing Hostname Verification

CVE-2026-48144 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:58:24.417Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Unbounded Read Leading to Denial of Service

CVE-2026-45112 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:57:25.527Z

Affected

  • Apache Thrift from 0.19.0 before 0.24.0

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.

This issue affects Apache Thrift: from 0.19.0 before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

  • IcySun & Yashon (finder)

TCompactProtocol varint byte-count limit

CVE-2026-43871 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:56:06.868Z

Affected

  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0
  • Apache Thrift before 0.24.0

Description

Loop with Unreachable Exit Condition (‘Infinite Loop’) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

Credits

Node.js web_server.js multi-vulnerability

CVE-2026-43870 [CVE] [CVE json] [OSV json]

Last updated: 2026-05-05T07:45:34.804Z

Affected

  • Apache Thrift before 0.23.0

Description

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

TSSLTransportFactory.java hostname verification

CVE-2026-43869 [CVE] [CVE json] [OSV json]

Last updated: 2026-05-05T07:25:46.713Z

Affected

  • Apache Thrift before 0.23.0

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Rust implementation vulnerable to CVE-2020-13949 pattern

CVE-2026-43868 [CVE] [CVE json] [OSV json]

Last updated: 2026-05-05T07:49:46.378Z

Affected

  • Apache Thrift before 0.23.0

Description

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Node.js skip() recursion

CVE-2026-41636 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-15T20:56:45.279Z

Affected

  • Apache Thrift before 0.23.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Sion Park (L3G4CY Security Research) (finder)
  • Yu Bao – yubao@paypal.com (finder)

Unbounded Zlib Decompression in Python THeaderTransport

CVE-2026-41608 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-27T10:53:37.845Z

Affected

  • Apache Thrift before 0.24.0

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

References

C++ JSON OOB read

CVE-2026-41607 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:21:46.727Z

Affected

  • Apache Thrift before 0.23.0

Description

Out-of-bounds Read vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

c_glib dispatch stack overflow

CVE-2026-41606 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:21:09.783Z

Affected

  • Apache Thrift before 0.23.0

Description

Uncontrolled Recursion vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Swift Compact Protocol integer overflow

CVE-2026-41605 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:20:43.166Z

Affected

  • Apache Thrift before 0.23.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Swift Range crash in skip()

CVE-2026-41604 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:20:12.306Z

Affected

  • Apache Thrift before 0.23.0

Description

Out-of-bounds Read vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • Hasnain Lakhani (finder)

Go TFramedTransport uint32 overflow

CVE-2026-41602 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:19:05.731Z

Affected

  • Apache Thrift before 0.23.0

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

References

Credits

  • 김범수 (finder)

Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

CVE-2025-48431 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-28T09:11:42.895Z

Affected

  • Apache Thrift before 0.23.0

Description

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

References

Credits

  • Hasnain Lakhani (finder)
  • Hasnain Lakhani (remediation developer)