Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Thrift — Vulnerabilities & Security Advisories 92

All 92 CVE vulnerabilities found in Apache Thrift, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Apache Thrift, an open-source multi-language interface and data serialization framework. It collects and categorizes security flaws within the project, covering advisories issued across a multi-year timeframe. Readers can use this page to track vendor-published security bulletins, understand common weakness classes affecting the library, and review the product's historical vulnerability record without needing to search individual database entries.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-66054 Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize CWE-770 6.9 Medium 2026-10-02
CVE-2026-61374 Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit CWE-770 7.1 High 2026-10-02
CVE-2026-63772 Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count CWE-770 8.7 High 2026-10-02
CVE-2026-66055 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) CWE-770 8.2 High 2026-10-02
CVE-2026-66081 Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages CWE-824 8.7 High 2026-10-02
CVE-2026-66331 Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize CWE-770 6.9 Medium 2026-10-02
CVE-2026-66837 Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length CWE-121 8.7 High 2026-10-02
CVE-2026-66858 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) CWE-674 8.7 High 2026-10-02
CVE-2026-66859 Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route CWE-476 8.7 High 2026-10-02
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound CWE-770 9.2 Critical 2026-10-02
CVE-2026-83663 Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go) CWE-674 8.7 High 2026-10-02
CVE-2026-83745 Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D) CWE-789 8.7 High 2026-10-02
CVE-2026-85476 Apache Thrift: c_glib `read_all` spins when the underlying read returns 0 CWE-835 8.2 High 2026-10-02
CVE-2026-96289 Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard CWE-674 8.2 High 2026-10-02
CVE-2026-96287 Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic) CWE-407 8.2 High 2026-10-02
CVE-2026-96286 Apache Thrift: Perl servers end `serve()` when serving one connection fails CWE-248 8.2 High 2026-10-02
CVE-2026-96277 Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception CWE-248 8.7 High 2026-10-02
CVE-2026-94658 Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic) CWE-407 8.7 High 2026-10-02
CVE-2026-94657 Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound CWE-770 8.2 High 2026-10-02
CVE-2026-94656 Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound CWE-770 8.2 High 2026-10-02
CVE-2026-94655 Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic CWE-770 8.2 High 2026-10-02
CVE-2026-94654 Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame CWE-835 8.2 High 2026-10-02
CVE-2026-94653 Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic) CWE-407 8.2 High 2026-10-02
CVE-2026-94652 Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back CWE-401 6.3 Medium 2026-10-02
CVE-2026-94648 Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound CWE-770 8.2 High 2026-10-02
CVE-2026-94646 Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers) CWE-248 8.7 High 2026-10-02
CVE-2026-94638 Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize` CWE-770 6.3 Medium 2026-10-02
CVE-2026-94637 Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame CWE-409 8.2 High 2026-10-02
CVE-2026-94636 Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up CWE-409 8.2 High 2026-10-02
CVE-2026-92834 Apache Thrift: C++ WebSocket server transport does not read a full request length CWE-908 6.3 Medium 2026-10-02

All 92 known CVE vulnerabilities affecting Apache Thrift with full Chinese analysis, references, and POCs where available.