CVE-2026-41606
- EPSS 1.1%
- Veröffentlicht 28.04.2026 09:21:12
- Zuletzt bearbeitet 20.08.2026 13:18:27
Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2026-41605
- EPSS 0.93%
- Veröffentlicht 28.04.2026 09:20:44
- Zuletzt bearbeitet 20.08.2026 13:18:27
Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2026-41604
- EPSS 0.92%
- Veröffentlicht 28.04.2026 09:20:13
- Zuletzt bearbeitet 20.08.2026 13:18:26
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2026-41603
- EPSS 0.57%
- Veröffentlicht 28.04.2026 09:19:40
- Zuletzt bearbeitet 27.07.2026 15:16:49
Rejected reason: This CVE ID is Rejected and will not be used. The record incorrectly described the affected language binding and fixed version. Use CVE-2026-66053, which was assigned to the vulnerability.
CVE-2026-41602
- EPSS 1.16%
- Veröffentlicht 28.04.2026 09:19:06
- Zuletzt bearbeitet 20.08.2026 13:18:25
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2025-48431
- EPSS 1.08%
- Veröffentlicht 28.04.2026 09:11:44
- Zuletzt bearbeitet 20.08.2026 13:16:34
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially craft...
CVE-2020-13949
- EPSS 6.78%
- Veröffentlicht 12.02.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:02:12
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
CVE-2019-0210
- EPSS 6.85%
- Veröffentlicht 29.10.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:16:29
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
CVE-2019-0205
- EPSS 9.16%
- Veröffentlicht 29.10.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:16:29
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it ...
CVE-2018-1320
- EPSS 8.19%
- Veröffentlicht 07.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:37
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed co...