Thrift Apache Thrift

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apache Thrift.

By the Year

In 2026 there have been 26 vulnerabilities in Apache Thrift with an average score of 7.5 out of ten. Thrift did not have any published security vulnerabilities last year. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 26 7.54
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 7.50
2020 0 0.00
2019 4 7.25
2018 1 8.80

It may take a day or so for new Thrift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Thrift Security Vulnerabilities

Apache Thrift Python Bindings: CA Host Mismatch (pre 0.24.0)
CVE-2026-66053 5.9 - Medium - July 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

Improper Validation of Certificate with Host Mismatch

Apache Thrift <=0.23.99 Improper Qty Validation, OOB Read in C++ Bindings
CVE-2026-58662 - July 27, 2026

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Improper Validation of Specified Quantity in Input

Apache Thrift Rust binding Resource Exhaustion before 0.24.0
CVE-2026-58389 - July 27, 2026

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Allocation of Resources Without Limits or Throttling

OOB Read in Apache Thrift c_glib Bindings (v<0.24.0)
CVE-2026-58023 - July 27, 2026

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Out-of-bounds Read

Apache Thrift C++ Heap-Buffer Overflow Before 0.24.0
CVE-2026-55971 - July 27, 2026

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Heap-based Buffer Overflow

Apache Thrift C++ Binding Over-read, <0.24.0 CVE-2026-55970
CVE-2026-55970 - July 27, 2026

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Buffer Over-read

Apache Thrift <0.24.0 Integer Overflow Vulnerability
CVE-2026-55969 - July 27, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Integer Overflow or Wraparound

Apache Thrift Node.js Bindings: Resource Exhaustion (DoS) before 0.24.0
CVE-2026-55968 - July 27, 2026

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Inefficient Algorithmic Complexity

Apache Thrift Ruby Bindings Data Amplification before 0.24.0
CVE-2026-49158 7.5 - High - July 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Data Amplification

Apache Thrift <0.24: Improper Data Amplification Vulnerability
CVE-2026-48586 - July 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Data Amplification

Apache Thrift C++ Cert Host Mismatch (v<0.24.0)
CVE-2026-48145 - July 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch

Apache Thrift c_glib Bindings Hostname Mismatch CVE-2026-48144 (before 0.24.0)
CVE-2026-48144 - July 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch

Apache Thrift Java Bindings Resource Allocation Without Limits (Before v0.24.0)
CVE-2026-45112 - July 27, 2026

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Allocation of Resources Without Limits or Throttling

Apache Thrift Loop: Unreachable Exit in Bindings v<0.24.0
CVE-2026-43871 - July 27, 2026

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Infinite Loop

Apache Thrift PY Bindings Data Amplification <0.24.0
CVE-2026-41608 7.5 - High - July 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Data Amplification

Memory Allocation with Excessive Size in Apache Thrift < 0.23.0 (CVE-2026-43868)
CVE-2026-43868 7.5 - High - May 05, 2026

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Stack Exhaustion

Apache Thrift <0.23.0 PT, HTS, Resource Exhaustion - CVE-2026-43870
CVE-2026-43870 7.3 - High - May 05, 2026

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Origin Validation Error

Apache Thrift CVE-2026-43869: Improper Cert Host Mismatch before 0.23.0
CVE-2026-43869 7.3 - High - May 05, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch

Uncontrolled Recursion Exposed in Apache Thrift Node.js Bindings <0.23.0
CVE-2026-41636 - April 28, 2026

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Stack Exhaustion

OOB Read Vulnerability in Apache Thrift before 0.23.0
CVE-2026-41607 9.1 - Critical - April 28, 2026

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Out-of-bounds Read

Apache Thrift <0.23.0: Uncontrolled Recursion Vulnerability
CVE-2026-41606 7.5 - High - April 28, 2026

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Stack Exhaustion

Apache Thrift Int Overflow or Wraparound <0.23.0; Fixed 0.23.0
CVE-2026-41605 7.7 - High - April 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Integer Overflow or Wraparound

CVE-2026-41604: OOB Read in Apache Thrift < 0.23.0
CVE-2026-41604 8.2 - High - April 28, 2026

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Out-of-bounds Read

Apache Thrift Go TFramedTransport Integer Overflow (<0.23.0)
CVE-2026-41602 7.5 - High - April 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Integer Overflow or Wraparound

Apache Thrift 0.23+ Mismatched Memory Mgmt Routines Vulnerability
CVE-2025-48431 7.5 - High - April 28, 2026

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

Mismatched Memory Management Routines

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages
CVE-2020-13949 7.5 - High - February 12, 2021

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

Resource Exhaustion

In Apache Thrift 0.9.3 to 0.12.0
CVE-2019-0210 7.5 - High - October 29, 2019

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Out-of-bounds Read

In Apache Thrift all versions up to and including 0.12.0
CVE-2019-0205 7.5 - High - October 29, 2019

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.

Infinite Loop

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in
CVE-2018-11798 6.5 - Medium - January 07, 2019

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

Insertion of Sensitive Information into Externally-Accessible File or Directory

Apache Thrift Java client library versions 0.5.0 through 0.11.0
CVE-2018-1320 7.5 - High - January 07, 2019

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

Improper Certificate Validation

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool
CVE-2016-5397 8.8 - High - February 12, 2018

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Command Injection

The client libraries in Apache Thrift before 0.9.3 might
CVE-2015-3254 6.5 - Medium - June 16, 2017

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.

Improper Input Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Thrift or by Apache? Click the Watch button to subscribe.

Apache
Vendor

Apache Thrift
Product

subscribe