Apache thrift是美国Apache基金会开源的一个跨语言RPC框架。 Apache Thrift 0.24.0之前版本存在安全漏洞,该漏洞源于对输入中指定数量的验证不当,导致越界读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Thrift | < 0.24.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Thrift | 0 ~ 0.24.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55971 | 9.3 CRITICAL | Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() |
| CVE-2026-48144 | 9.1 CRITICAL | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-43871 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c |
| CVE-2026-48586 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: |
| CVE-2026-55968 | 8.7 HIGH | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-55969 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: |
| CVE-2026-58389 | 8.7 HIGH | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-48145 | 8.2 HIGH | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-49158 | 7.5 HIGH | Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb |
| CVE-2026-45112 | 6.9 MEDIUM | Apache Thrift: Unbounded Read Leading to Denial of Service |
| CVE-2026-55970 | 6.9 MEDIUM | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() |
| CVE-2026-58023 | 6.9 MEDIUM | Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path |
| CVE-2026-66053 | 5.9 MEDIUM | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-41608 | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport | |
| CVE-2026-66390 | Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence | |
| CVE-2026-66391 | Apache Wicket: leaked and missing CSP headers |
No comments yet