Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Thrift — Vulnerabilities & Security Advisories 92

All 92 CVE vulnerabilities found in Apache Thrift, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Apache Thrift, an open-source multi-language interface and data serialization framework. It collects and categorizes security flaws within the project, covering advisories issued across a multi-year timeframe. Readers can use this page to track vendor-published security bulletins, understand common weakness classes affecting the library, and review the product's historical vulnerability record without needing to search individual database entries.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-90440 Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service CWE-248 8.2 High 2026-10-02
CVE-2026-87117 Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec CWE-476 8.7 High 2026-10-02
CVE-2026-86537 Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service CWE-248 8.7 High 2026-10-02
CVE-2026-86536 Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript CWE-1321 6.3 Medium 2026-10-02
CVE-2026-86535 Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely CWE-835 8.7 High 2026-10-02
CVE-2026-85088 Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match CWE-295 6.9 Medium 2026-10-02
CVE-2026-85087 Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op CWE-295 6.9 Medium 2026-10-02
CVE-2026-85086 Apache Thrift: Perl TLS client disables certificate verification by default CWE-295 6.9 Medium 2026-10-02
CVE-2026-82459 Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process CWE-191 8.2 High 2026-10-02
CVE-2026-82458 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available CWE-789 8.7 High 2026-10-02
CVE-2026-96288 Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory) CWE-674 8.2 High 2026-10-02
CVE-2026-96292 Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic) CWE-1333 8.2 High 2026-10-02
CVE-2026-96294 Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection CWE-248 8.7 High 2026-10-02
CVE-2026-61373 Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation CWE-770 8.7 High 2026-10-02
CVE-2026-96990 Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound CWE-770 8.2 High 2026-10-02
CVE-2026-94642 Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception CWE-248 8.7 High 2026-10-02
CVE-2026-94644 Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound CWE-770 8.2 High 2026-10-02
CVE-2026-94645 Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound CWE-1284 8.2 High 2026-10-02
CVE-2026-94650 Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion) CWE-674 8.2 High 2026-10-02
CVE-2026-94651 Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error CWE-755 8.2 High 2026-10-02
CVE-2026-85483 Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end CWE-908 6.3 Medium 2026-10-02
CVE-2026-85493 Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME) CWE-674 8.7 High 2026-10-02
CVE-2026-85494 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language) CWE-130 8.7 High 2026-10-02
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) CWE-122 9.2 Critical 2026-10-02
CVE-2026-91137 Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements CWE-1284 8.7 High 2026-10-02
CVE-2026-93925 Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id CWE-121 8.7 High 2026-10-02
CVE-2026-93926 Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path CWE-401 8.7 High 2026-10-02
CVE-2026-94633 Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length CWE-789 8.7 High 2026-10-02
CVE-2026-94634 Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default CWE-770 8.2 High 2026-10-02
CVE-2026-94639 Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget) CWE-755 8.2 High 2026-10-02

All 92 known CVE vulnerabilities affecting Apache Thrift with full Chinese analysis, references, and POCs where available.