Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Thrift — Vulnerabilities & Security Advisories 92

All 92 CVE vulnerabilities found in Apache Thrift, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Apache Thrift, an open-source multi-language interface and data serialization framework. It collects and categorizes security flaws within the project, covering advisories issued across a multi-year timeframe. Readers can use this page to track vendor-published security bulletins, understand common weakness classes affecting the library, and review the product's historical vulnerability record without needing to search individual database entries.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-94635 Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name CWE-770 8.7 High 2026-10-02
CVE-2026-66053 Apache Thrift: Python TSSLSocket Hostname Matcher Import CWE-297 5.9 Medium 2026-07-27
CVE-2026-58662 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass CWE-1284 8.7 High 2026-07-27
CVE-2026-58389 Apache Thrift: Rust binary protocol non-strict path missing string size limit CWE-770 8.7 High 2026-07-27
CVE-2026-58023 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path CWE-125 6.9 Medium 2026-07-27
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() CWE-122 9.3 Critical 2026-07-27
CVE-2026-55970 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() CWE-126 6.9 Medium 2026-07-27
CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() CWE-190 8.7 High 2026-07-27
CVE-2026-55968 Apache Thrift: Node.js quadratic-time DoS in server receive transports CWE-407 8.7 High 2026-07-27
CVE-2026-49158 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb CWE-409 7.5 High 2026-07-27
CVE-2026-48586 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit CWE-409 8.7 High 2026-07-27
CVE-2026-48145 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass CWE-297 8.2 High 2026-07-27
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification CWE-297 9.1 Critical 2026-07-27
CVE-2026-45112 Apache Thrift: Unbounded Read Leading to Denial of Service CWE-770 6.9 Medium 2026-07-27
CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit CWE-835 8.7 High 2026-07-27
CVE-2026-41608 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport CWE-409 - - 2026-07-27
CVE-2026-43868 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern CWE-789 9.1 - 2026-05-05
CVE-2026-43870 Apache Thrift: Node.js web_server.js multi-vulnerability CWE-346 7.5 - 2026-05-05
CVE-2026-43869 Apache Thrift: TSSLTransportFactory.java hostname verification CWE-297 7.5 - 2026-05-05
CVE-2026-41636 Apache Thrift: Node.js skip() recursion CWE-674 7.5AI High AI 2026-04-28
CVE-2026-41607 Apache Thrift: C++ JSON OOB read CWE-125 7.5AI High AI 2026-04-28
CVE-2026-41606 Apache Thrift: c_glib dispatch stack overflow CWE-674 7.5AI High AI 2026-04-28
CVE-2026-41605 Apache Thrift: Swift Compact Protocol integer overflow CWE-190 9.8AI Critical AI 2026-04-28
CVE-2026-41604 Apache Thrift: Swift Range crash in skip() CWE-125 7.5AI High AI 2026-04-28
CVE-2026-41602 Apache Thrift: Go TFramedTransport uint32 overflow CWE-190 9.8AI Critical AI 2026-04-28
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. CWE-762 7.5AI High AI 2026-04-28
CVE-2020-13949 Apache Thrift 资源管理错误漏洞 7.5 - 2021-02-12
CVE-2019-0205 Apache Thrift 安全漏洞 7.5 - 2019-10-28
CVE-2019-0210 Apache Thrift 缓冲区错误漏洞 7.5 - 2019-10-28
CVE-2018-11798 Apache Thrift Node.js static web服务器访问控制错误漏洞 6.5 - 2019-01-07

All 92 known CVE vulnerabilities affecting Apache Thrift with full Chinese analysis, references, and POCs where available.