Apache Thrift security advisories
Security information for Apache Thrift
Reporting
Do you want disclose a potential security issue for Apache Thrift? Send your report to the Apache Security Team.
You can read more about the security policy on:
Advisories
This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org
Erlang thrift_json_protocol reads a whole message with no size bound
CVE-2026-96990 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:00:25.502Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/hrgcqlms4ksrz4qkqdjwoxxggdty7dgh
nodejs web server: no error listener on an upgraded WebSocket connection
CVE-2026-96294 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:09:53.242Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/52gwhsy947hj9qhgn0dql726z1q927g4
Lua THttpTransport:_parseHeaders matches each header line with a backtracking pattern (quadratic)
CVE-2026-96292 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:11:30.594Z
Affected
- Apache Thrift before 0.25.0
Description
Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn
php --gen php:inlined struct readers (and TProtocol::skipBinary) have no recursion-depth guard
CVE-2026-96289 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:07:00.960Z
Affected
- Apache Thrift before 0.25.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/kv1zkwlt82lkkv20g29txr5pjnvo0pf8
Erlang generated struct reads have no recursion-depth guard (unbounded memory)
CVE-2026-96288 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:18:35.296Z
Affected
- Apache Thrift before 0.25.0
Description
Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/vxnk7cmdtoqjn97b8szlqym1mxx0xtzb
Perl FramedTransport reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)
CVE-2026-96287 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:05:57.430Z
Affected
- Apache Thrift before 0.25.0
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/tcg16jr59z5nry066dw7ym60vl25dxt9
Perl servers end serve() when serving one connection fails
CVE-2026-96286 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:04:24.079Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception vulnerability in Apache Thrift Perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/o5386v7ytbbjv9sx7dbszw46ypod5yd9
Ruby SimpleServer ends serve() on any non-Transport/Protocol exception
CVE-2026-96277 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:03:22.302Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098
Lua TFramedTransport/THttpTransport re-slice the buffer on every read (quadratic)
CVE-2026-94658 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:02:20.074Z
Affected
- Apache Thrift before 0.25.0
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/hv6b1nyk2p15gy5pmtprwo7z9m46mfcx
javame TJsonProtocol/TJSONProtocol has no string size bound
CVE-2026-94657 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:01:35.174Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14
Credits
- Sylwester Lachiewicz (finder)
rb TJsonProtocol/TJSONProtocol has no string size bound
CVE-2026-94656 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:00:46.391Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/lg97w2yvg3c6z06l8m5xs3j3v2m6mvj8
Credits
- Sylwester Lachiewicz (finder)
Lua TJsonProtocol string/number readers have no size bound and are quadratic
CVE-2026-94655 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:59:15.906Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/wdjyf4y115ybgdzz5m3gspo97lcmz1dt
Credits
- Sylwester Lachiewicz (finder)
Python TNonblockingServer busy-loops and stops selecting all fds after an 8192-byte-boundary frame
CVE-2026-94654 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:58:47.375Z
Affected
- Apache Thrift before 0.25.0
Description
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/kx3xdttoypl8j4dcxmqbq9dwy1w0kr7j
PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)
CVE-2026-94653 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:56:33.859Z
Affected
- Apache Thrift before 0.25.0
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/8zbv1y4wzr3nn5mzmdph7b0n6tm0lc4m
C++ TEvhttpServer leaks its RequestContext when the processor throws before calling back
CVE-2026-94652 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:54:39.118Z
Affected
- Apache Thrift before 0.25.0
Description
Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/nodwz7gjvogkkh3w1jwbsslk1c7t0727
Credits
- Sylwester Lachiewicz (finder)
Java TSaslNonblockingServer Computation.run orphans a connection on a pre-auth parse error
CVE-2026-94651 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:48:32.419Z
Affected
- Apache Thrift before 0.25.0
Description
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/rflzpdvtk8yhpzg99wkf5yf277nn7267
c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)
CVE-2026-94650 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:49:35.651Z
Affected
- Apache Thrift before 0.25.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j
Credits
- Sylwester Lachiewicz (finder)
dart TJsonProtocol/TJSONProtocol has no string size bound
CVE-2026-94648 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:52:47.045Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/f9w4q6ttlc3k9404x4do25gdhqodtjnn
Credits
- Sylwester Lachiewicz (finder)
Node.js server.js ends the process on any per-connection error (+ two triggers)
CVE-2026-94646 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:57:22.883Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8
Credits
- Sylwester Lachiewicz (finder)
Node.js TJSONProtocol uses a peer-declared container size as an unbounded loop bound
CVE-2026-94645 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:51:36.420Z
Affected
- Apache Thrift before 0.25.0
Description
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/p96mokqfy16mnqfyon46mf6g8nr9ghb6
Credits
- Sylwester Lachiewicz (finder)
PHP TJSONProtocol string/number readers have no size bound
CVE-2026-94644 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:53:33.571Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/8y04vvxw7ozxxh3c44vhoy7jsd6bonzq
Credits
- Sylwester Lachiewicz (finder)
PHP TSimpleServer exits the whole process on any non-transport exception
CVE-2026-94642 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:57:13.128Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/5tjwbbyympbj16lblocv9b12s32sg113
Credits
- Sylwester Lachiewicz (finder)
Java TSaslNonblockingServer: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
CVE-2026-94639 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T09:33:49.406Z
Affected
- Apache Thrift before 0.25.0
Description
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/5okpz47dv8hy0s3r6tmrplg3y7jzhhyw
Credits
- Sylwester Lachiewicz (finder)
PHP thrift_protocol C extension ignores the configured maxStringSize
CVE-2026-94638 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:49:41.453Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj
Credits
- Sylwester Lachiewicz (finder)
Go THeaderTransport does not bound the inflated size of a ZLIB frame
CVE-2026-94637 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:49:01.158Z
Affected
- Apache Thrift before 0.25.0
Description
Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/6hxll1jcnod9gfr225tz7my08lpj3jmt
Credits
- Sylwester Lachiewicz (finder)
Python TZlibTransport stops enforcing its decompressed-size limit once the limit is exactly used up
CVE-2026-94636 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:47:52.635Z
Affected
- Apache Thrift before 0.25.0
Description
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/1rpq0d0g6yzjjzl1z27lwmvhzkn6rbrs
Credits
- Sylwester Lachiewicz (finder)
Lua TBinaryProtocol:readMessageBegin bypasses checkStringSize on the pre-versioned name
CVE-2026-94635 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T09:05:56.419Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3
Credits
- Ho1aAs xxy010605@gmail.com (finder)
Python TJSONProtocol has a string length limit that is off by default
CVE-2026-94634 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:11:18.689Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/dgy8ox9t4bh1xhf74ovf29ht87x7dno4
Credits
- Ho1aAs xxy010605@gmail.com (finder)
Dart TBinaryProtocol.readMessageBegin allocates from the pre-versioned name length
CVE-2026-94633 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:12:57.695Z
Affected
- Apache Thrift before 0.25.0
Description
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k
Credits
- Ho1aAs xxy010605@gmail.com (finder)
- Sylwester Lachiewicz (finder)
C++ THeaderTransport::untransform() leaks the zlib stream on the error path
CVE-2026-93926 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:14:57.912Z
Affected
- Apache Thrift before 0.25.0
Description
Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb
Credits
- glit3h from ZeroVuln Labs (finder)
C++ THeaderTransport::writeVarint32() stack buffer overflow on a negative protocol id
CVE-2026-93925 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:16:09.141Z
Affected
- Apache Thrift before 0.25.0
Description
Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9
Credits
- glit3h from ZeroVuln Labs (finder)
C++ WebSocket server transport does not read a full request length
CVE-2026-92834 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:45:22.654Z
Affected
- Apache Thrift before 0.25.0
Description
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/bjor9ttx7hk23gzcx60ohz0f20xzvgv0
PHP thrift_protocol accelerator: zero-byte container elements
CVE-2026-91137 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:18:34.190Z
Affected
- Apache Thrift before 0.25.0
Description
Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/bf12g1b11r4x9x3wsy4mgwfgd0t779h7
Credits
- glit3h from ZeroVuln Labs (finder)
C++ THeaderTransport::transform() heap buffer overflow (write direction)
CVE-2026-91135 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:28:47.666Z
Affected
- Apache Thrift before 0.25.0
Description
Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.
When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/rbpwlhlxnv2qgyk8cfscp2d2fd3p0ojb
Credits
- glit3h from ZeroVuln Labs (finder)
An exception escaping a libevent callback stops the D library’s non-blocking server, allowing an unauthenticated remote attacker to deny service
CVE-2026-90440 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:44:09.882Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg
PHP thrift_protocol accelerator dereferences a missing container-element spec
CVE-2026-87117 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:43:10.120Z
Affected
- Apache Thrift before 0.25.0
Description
NULL pointer dereference vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/y05tvpv19ow44j16gtbcy9ht7lb0qjpy
Credits
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
A truncated HTTP request stops the D library’s server, allowing an unauthenticated remote attacker to deny service
CVE-2026-86537 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:40:50.109Z
Affected
- Apache Thrift before 0.25.0
Description
Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m
A map key from the wire can replace a decoded object’s prototype in generated JavaScript
CVE-2026-86536 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:39:59.296Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/xckvfky30kdnk8vqnhy0wndthvc9nymp
Credits
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
A JSON member name can stall the Node server’s event loop indefinitely
CVE-2026-86535 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:38:14.489Z
Affected
- Apache Thrift before 0.25.0
Description
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g
Credits
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)
CVE-2026-85494 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:42:42.564Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr
Credits
- Ho1aAs xxy010605@gmail.com for py, rb, erl, lua, dart, javame, d bindings (finder)
- Perl/PHP bindings were found by the Apache Thrift project’s own cross-language sweep (finder)
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)
CVE-2026-85493 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:45:55.375Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/oqr0h2k1cg9hho3oh8trmovmxc04fl5m
Credits
- Ho1aAs xxy010605@gmail.com (finder)
c_glib TZlibTransport reports a full read after a premature stream end
CVE-2026-85483 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T10:46:53.193Z
Affected
- Apache Thrift before 0.25.0
Description
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/ro1y0ckzfzcc45yk9qkt1p6t4g2jvrfy
Credits
- Ho1aAs xxy010605@gmail.com (finder)
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
c_glib read_all spins when the underlying read returns 0
CVE-2026-85476 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:12:37.604Z
Affected
- Apache Thrift before 0.25.0
Description
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/1zdvscq7p3hf3z30s26h4tm9dvljm1jj
Credits
- Ho1aAs xxy010605@gmail.com (finder)
The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match
CVE-2026-85088 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:37:12.940Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.
Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host
name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than
a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check.
RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a
Common Name for another is therefore accepted for a connection to the second name.
Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host
name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure.
This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371
Credits
- The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
Python ≥3.12 host-name check silently becomes a no-op
CVE-2026-85087 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:35:42.674Z
Affected
- Apache Thrift before 0.25.0
Description
Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/l2rgp3dqhpy2w347forzdt9g7o2d6k0d
Credits
- The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
Perl TLS client disables certificate verification by default
CVE-2026-85086 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:33:58.761Z
Affected
- Apache Thrift before 0.25.0
Description
Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy
Credits
- The ASF — found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift (finder)
WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)
CVE-2026-83745 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:16:12.360Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift
nodejs and D lang bindings.
Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.
This issue affects Apache Thrift before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc
Credits
- Ho1aAs xxy010605@gmail.com for Node.js (finder)
- Apache Thrift Developers for D language (finder)
TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)
CVE-2026-83663 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:18:15.518Z
Affected
- Apache Thrift before 0.25.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift go bindings.
Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/yjz317wq7h86q9k8ws6ton0ojgl8hjct
Credits
- Ho1aAs xxy010605@gmail.com for TFramedTransport (finder)
- Apache Thrift Developers for THeaderTransport (finder)
C++ THttpTransport grows its line buffer without bound
CVE-2026-83632 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:22:22.014Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/zjv6hjmhl4tb4l4l1dk4bmc2whxh0lb4
Credits
- Ho1aAs xxy010605@gmail.com (finder)
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift. (finder)
Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
CVE-2026-82459 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:32:28.180Z
Affected
- Apache Thrift before 0.25.0
Description
Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2
Credits
- The ASF – found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift (finder)
Container element count not bounded by the bytes available
CVE-2026-82458 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:30:13.881Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7
Credits
- denyspakizh-tob (Trail of Bits) for the Go bindings (finder)
- David Walker (Workiva, Inc) independent co-discoverer (finder)
- Ho1aAs xxy010605@gmail.com independent rediscovery (Go THeaderTransport transform count) (finder)
- Apache Thrift Developers (finder)
c_glib multiplexed processor crashes on a message it cannot route
CVE-2026-66859 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:23:46.689Z
Affected
- Apache Thrift before 0.25.0
Description
NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o
skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
CVE-2026-66858 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:27:29.550Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5
Credits
- Claude (Anthropic Research) (finder)
- Arthur Chan, Ada Logics (analyst)
- Apache Thrift Developers (finder)
PHP accelerator sizes a stack buffer from a wire-controlled string length
CVE-2026-66837 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:29:07.376Z
Affected
- Apache Thrift before 0.25.0
Description
Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1
Credits
- Claude (Anthropic Research) (finder)
- Arthur Chan, Ada Logics (arthur.chan@adalogics.com) (analyst)
Buffered transport reads are not accounted against MaxMessageSize
CVE-2026-66331 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:32:44.751Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143
c_glib read_message_begin leaves output parameters unset for non-versioned messages
CVE-2026-66081 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:33:12.312Z
Affected
- Apache Thrift before 0.25.0
Description
Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57
Credits
- Akhil Koul (finder)
- Claude (Anthropic Research) (finder)
- Arthur Chan, Ada Logics (arthur.chan@adalogics.com) (analyst)
TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)
CVE-2026-66055 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:49:39.024Z
Affected
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/nxlmlhgsh7fwr4mo1fkhtkw3v266qhcx
Credits
- Bin Luo, University of Electronic Science and Technology of China (UESTC) (C++) (finder)
- Apache Thrift Developers (Java/Go/netstd/Python/Delphi) (finder)
C++ THeaderTransport does not enforce configured maxFrameSize
CVE-2026-66054 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:51:20.441Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33
Credits
- Bin Luo, University of Electronic Science and Technology of China (UESTC) (finder)
Python TSSLSocket Hostname Matcher Import
CVE-2026-66053 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:18:43.366Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/w4k5dnv1x58knwlhpo9x0or5xh220y65
Credits
- Yu Bao – yubao@paypal.com, who works for paypal.com (finder)
Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count
CVE-2026-63772 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:52:05.727Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/6kpzdw29gsfxptv4b65y9s6f42tdyo8k
Credits
- Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski (finder)
Java TSaslTransport post-auth data-frame missing size limit
CVE-2026-61374 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T12:52:58.028Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/35831rngzrqky1gvc32t06psgq1b8441
Credits
- 周雪松 / Xuesong Zhou (xuesong.zhou@qingteng.cn), 73Lab of Qingteng.cn (finder)
- n0mi1k (finder)
Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation
CVE-2026-61373 [CVE] [CVE json] [OSV json]
Last updated: 2026-10-02T11:07:26.862Z
Affected
- Apache Thrift before 0.25.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/shy1rrm2g383wlbdb2p7w19c868ntdjp
Credits
- Claude (Anthropic Research) (finder)
- Arthur Chan, Ada Logics (arthur.chan@adalogics.com) (reporter)
- n0mi1k (finder)
C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2026-58662 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:17:20.407Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
Credits
- Javid Khan dxbjavid@gmail.com (finder)
Rust binary protocol non-strict path missing string size limit
CVE-2026-58389 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:14:25.617Z
Affected
- Apache Thrift before 0.24.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
Credits
- Javid Khan dxbjavid@gmail.com (finder)
c_glib heap out-of-bounds read in transport leftover-bytes path
CVE-2026-58023 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:12:35.855Z
Affected
- Apache Thrift before 0.24.0
Description
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
CVE-2026-55971 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:11:18.790Z
Affected
- Apache Thrift before 0.24.0
Description
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
Credits
- Ghaith Abdulreda (finder)
C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
CVE-2026-55970 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:09:36.113Z
Affected
- Apache Thrift before 0.24.0
Description
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7
Credits
- Ghaith Abdulreda (finder)
integer overflow in TProtocol::checkReadBytesAvailable()
CVE-2026-55969 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:07:43.565Z
Affected
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
Description
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
Credits
- Ghaith Abdulreda (finder)
- Javid Khan (finder)
- Apache Thrift Developers (finder)
Node.js quadratic-time DoS in server receive transports
CVE-2026-55968 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:06:12.486Z
Affected
- Apache Thrift before 0.24.0
Description
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
Credits
- Song Jihoon (finder)
Ruby THeaderTransport ZLIB Decompression Bomb
CVE-2026-49158 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:05:01.307Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7
Credits
- LTSHFWJT 1719636402@qq.com (finder)
TZlibTransport Decompression Size Limit
CVE-2026-48586 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T11:02:50.181Z
Affected
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
Description
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
CVE-2026-48145 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T10:59:40.690Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h
c_glib TLS Client Missing Hostname Verification
CVE-2026-48144 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T10:58:24.417Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
Unbounded Read Leading to Denial of Service
CVE-2026-45112 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T10:57:25.527Z
Affected
- Apache Thrift from 0.19.0 before 0.24.0
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc
Credits
- IcySun & Yashon (finder)
TCompactProtocol varint byte-count limit
CVE-2026-43871 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-27T10:56:06.868Z
Affected
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
- Apache Thrift before 0.24.0
Description
Loop with Unreachable Exit Condition (‘Infinite Loop’) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
Credits
- Yu Bao - yubao@paypal.com, who works for paypal.com (finder)
Node.js web_server.js multi-vulnerability
CVE-2026-43870 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-01T15:14:33.689Z
Affected
- Apache Thrift before 0.23.0
Description
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- sec-reports@outlook.com (finder)
TSSLTransportFactory.java hostname verification
CVE-2026-43869 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-01T15:15:50.815Z
Affected
- Apache Thrift before 0.23.0
Description
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- sec-reports@outlook.com (finder)
Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-43868 [CVE] [CVE json] [OSV json]
Last updated: 2026-05-05T07:49:46.378Z
Affected
- Apache Thrift before 0.23.0
Description
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Node.js skip() recursion
CVE-2026-41636 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-15T20:56:45.279Z
Affected
- Apache Thrift before 0.23.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- Sion Park (L3G4CY Security Research) (finder)
- Yu Bao – yubao@paypal.com (finder)
Unbounded Zlib Decompression in Python THeaderTransport
CVE-2026-41608 [CVE] [CVE json] [OSV json]
Last updated: 2026-09-14T21:15:42.689Z
Affected
- Apache Thrift before 0.24.0
Description
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
- https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
Credits
- sec-reports@outlook.com (finder)
C++ JSON OOB read
CVE-2026-41607 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:21:46.727Z
Affected
- Apache Thrift before 0.23.0
Description
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- Hasnain Lakhani (finder)
c_glib dispatch stack overflow
CVE-2026-41606 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:21:09.783Z
Affected
- Apache Thrift before 0.23.0
Description
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- Hasnain Lakhani (finder)
Swift Compact Protocol integer overflow
CVE-2026-41605 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:20:43.166Z
Affected
- Apache Thrift before 0.23.0
Description
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- Hasnain Lakhani (finder)
Swift Range crash in skip()
CVE-2026-41604 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:20:12.306Z
Affected
- Apache Thrift before 0.23.0
Description
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- Hasnain Lakhani (finder)
Go TFramedTransport uint32 overflow
CVE-2026-41602 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:19:05.731Z
Affected
- Apache Thrift before 0.23.0
Description
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
References
Credits
- 김범수 (finder)
Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
CVE-2025-48431 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-28T09:11:42.895Z
Affected
- Apache Thrift before 0.23.0
Description
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
References
Credits
- Hasnain Lakhani (finder)
- Hasnain Lakhani (remediation developer)