Apache Thrift
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Apache Thrift.
By the Year
In 2026 there have been 87 vulnerabilities in Apache Thrift with an average score of 8.0 out of ten. Thrift did not have any published security vulnerabilities last year. That is, 87 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 87 | 8.05 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 7.50 |
| 2020 | 0 | 0.00 |
| 2019 | 4 | 7.25 |
| 2018 | 1 | 8.80 |
It may take a day or so for new Thrift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apache Thrift Security Vulnerabilities
Apache Thrift <=0.24: Data Amplification in C++ Bindings
CVE-2026-66054
6.9 - Medium
- October 02, 2026
Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Java Resource Exhaustion Before 0.25.0
CVE-2026-61374
7.1 - High
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Go Bindings Resource Exhaustion Before 0.25.0
CVE-2026-63772
8.7 - High
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift (<0.25.0) Bindings Resource Exhaustion
CVE-2026-66055
8.2 - High
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift c_glib Uninitialized Pointer (before 0.25.0)
CVE-2026-66081
8.7 - High
- October 02, 2026
Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Access of Uninitialized Pointer
Apache Thrift Delphi BufferedTransport Resource Exhaustion before 0.25.0
CVE-2026-66331
6.9 - Medium
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift PHP Bindings: Buffer Overflow <0.25.0
CVE-2026-66837
8.7 - High
- October 02, 2026
Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Overflow
Apache Thrift Recursion Limit Bypass in Python C++ Accelerator (0.24)
CVE-2026-66858
8.7 - High
- October 02, 2026
The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift NULL Pointer in c_glib Bindings <0.25.0
CVE-2026-66859
8.7 - High
- October 02, 2026
NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
NULL Pointer Dereference
Apache Thrift <0.25.0 Heap Buffer Overflow & Integer Overflow
CVE-2026-83632
9.2 - Critical
- October 02, 2026
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Go Bindings Uncontrolled Recursion (pre-0.25.0)
CVE-2026-83663
8.7 - High
- October 02, 2026
Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift <0.25.0: Node.js/D WS Alloc DoS (Memory Buffer Over-alloc)
CVE-2026-83745
8.7 - High
- October 02, 2026
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift <0.25.0 c_glib infinite loop vulnerability
CVE-2026-85476
8.2 - High
- October 02, 2026
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Infinite Loop
Recursion Vulnerability in Thrift PHP Bindings (before 0.25.0)
CVE-2026-96289
8.2 - High
- October 02, 2026
Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift Perl Bindings Inefficient Algorithmic Complexity (before 0.25.0)
CVE-2026-96287
8.2 - High
- October 02, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Inefficient Algorithmic Complexity
Apache Thrift Perl Bindings Uncaught Exception before 0.25.0
CVE-2026-96286
8.2 - High
- October 02, 2026
Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift Ruby Uncaught Exception before 0.25.0
CVE-2026-96277
8.7 - High
- October 02, 2026
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift Lua Bindings Inefficient Algorithmic Complexity (before 0.25.0)
CVE-2026-94658
8.7 - High
- October 02, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Inefficient Algorithmic Complexity
Apache Thrift JavaME Unbounded Resource Allocation before 0.25.0
CVE-2026-94657
8.2 - High
- October 02, 2026
Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Ruby Bindings: Unbounded Resource Allocation Before 0.25.0
CVE-2026-94656
8.2 - High
- October 02, 2026
Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Lua Bindings DoS via Unbounded Resource Allocation (0.24.0)
CVE-2026-94655
8.2 - High
- October 02, 2026
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Python Bindings Infinite Loop Vulnerability (before 0.25.0)
CVE-2026-94654
8.2 - High
- October 02, 2026
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Infinite Loop
Apache Thrift PHP Bindings Inefficient Algorithmic Complexity (before 0.25.0)
CVE-2026-94653
8.2 - High
- October 02, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Inefficient Algorithmic Complexity
Apache Thrift C++ Bindings Memory Leak Before 0.25.0
CVE-2026-94652
6.3 - Medium
- October 02, 2026
Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Memory Leak
Apache Thrift Dart Bindings Resource Exhaustion Before 0.25.0
CVE-2026-94648
8.2 - High
- October 02, 2026
Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Prototype Pollution: Apache Thrift Node.js Bindings <0.25.0
CVE-2026-94646
8.7 - High
- October 02, 2026
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift PHP Bindings DoS via Unlimited Resource Allocation (<0.25.0)
CVE-2026-94638
6.3 - Medium
- October 02, 2026
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Data Amplification via Compression in Apache Thrift Go <0.25.0
CVE-2026-94637
8.2 - High
- October 02, 2026
Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Data Amplification
Apache Thrift <0.25.0: Improper Handling of Compressed Data in Python Bindings
CVE-2026-94636
8.2 - High
- October 02, 2026
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Data Amplification
Apache Thrift C++ WS Server Uninitialized Resource & Wrong Status (0.24.9)
CVE-2026-92834
6.3 - Medium
- October 02, 2026
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Use of Uninitialized Resource
Apache Thrift v<0.25.0 TNonblockingServer Exception Resource Shutdown CVE
CVE-2026-90440
8.2 - High
- October 02, 2026
Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
CVE-2026-87117: Null Pointer Deref in Apache Thrift PHP Bindings before 0.25.0
CVE-2026-87117
8.7 - High
- October 02, 2026
NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
NULL Pointer Dereference
Apache Thrift D Bindings Integer Underflow Loops <0.25.0
CVE-2026-86537
8.7 - High
- October 02, 2026
Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift JS Prototype Pollution <0.25.0
CVE-2026-86536
6.3 - Medium
- October 02, 2026
Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue.
Prototype Pollution
Apache Thrift: Infinite Loop & Prototype Pollution (pre-0.25.0)
CVE-2026-86535
8.7 - High
- October 02, 2026
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Infinite Loop
Apache Thrift C++/D SSL Host-Mismatch (pre-0.25.0)
CVE-2026-85088
6.9 - Medium
- October 02, 2026
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets TSSLSocketFactory does so in C++, and the accessManager property does so in D which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a Common Name for another is therefore accepted for a connection to the second name. Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure. This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.
Improper Certificate Validation
Thrift Py Bindings CVE-2026-85087 Improper Cert Val Before 0.25.0
CVE-2026-85087
6.9 - Medium
- October 02, 2026
Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Improper Certificate Validation
Apache Thrift <0.25.0 Improper Cert Validation in Perl Bindings
CVE-2026-85086
6.9 - Medium
- October 02, 2026
Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Improper Certificate Validation
Apache Thrift Int Underflow/OOB in 32bit THeaderTransport (0.24)
CVE-2026-82459
8.2 - High
- October 02, 2026
Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Integer underflow
Memory Allocation DoS in Apache Thrift <0.25.0 (CVE-2026-82458)
CVE-2026-82458
8.7 - High
- October 02, 2026
Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift Erlang Bindings Uncontrolled Recursion (before 0.25.0)
CVE-2026-96288
8.2 - High
- October 02, 2026
Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift Lua Binding ReDoS before 0.25.0
CVE-2026-96292
8.2 - High
- October 02, 2026
Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
ReDoS
Apache Thrift NodeJS Bindings: Improper Exception Handling (pre-0.25.0)
CVE-2026-96294
8.7 - High
- October 02, 2026
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift 0.25.0 Fixes Unbounded Resource Allocation TSaslNonblockingServer
CVE-2026-61373
8.7 - High
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift Erlang: Resource Exhaustion before 0.25.0
CVE-2026-96990
8.2 - High
- October 02, 2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Uncaught Exception in Apache Thrift PHP Bindings (before 0.25.0)
CVE-2026-94642
8.7 - High
- October 02, 2026
Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Uncaught Exception
Apache Thrift PHP Bindings Resource Exhaustion Pre0.25.0
CVE-2026-94644
8.2 - High
- October 02, 2026
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling
Apache Thrift NodeJS Bindings: Unbounded Resource Allocation (0.25.0)
CVE-2026-94645
8.2 - High
- October 02, 2026
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Improper Validation of Specified Quantity in Input
Uncontrolled Recursion in Apache Thrift c_glib Bindings before 0.25.0
CVE-2026-94650
8.2 - High
- October 02, 2026
Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Stack Exhaustion
Apache Thrift <0.25.0 java bindings resource leak
CVE-2026-94651
8.2 - High
- October 02, 2026
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Improper Handling of Exceptional Conditions
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apache Thrift or by Apache? Click the Watch button to subscribe.