Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift: Python TSSLSocket Hostname Matcher Import
Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Apache Thrift: cglib heap out-of-bounds read in transport leftover-bytes path
Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Apache Thrift: cglib TLS Client Missing Hostname Verification
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Credit:
Yu Bao – yubao () paypal com, who works for paypal.com (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-66053
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Credit:
Javid Khan <dxbjavid () gmail com> (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-58389
Severity:
Affected versions:
- Apache Thrift (glibc language bindings) before 0.24.0
Description:
Out-of-bounds Read vulnerability in Apache Thrift cglib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-58023
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Credit:
Ghaith Abdulreda (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55971
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Credit:
Ghaith Abdulreda (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55970
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Credit:
Song Jihoon (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55968
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0 - Apache Thrift (github.com/apache/thrift) before 0.24.0 - Apache Thrift (cglib) before 0.24.0 - Apache Thrift (org.apache.thrift:libthrift) before 0.24.0 - Apache Thrift (thrift) before 0.24.0 - Apache Thrift (D language) before 0.24.0
Description:
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48586
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48145
Severity:
Affected versions:
- Apache Thrift (glibc language bindings) before 0.24.0
Description:
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift cglib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48144
Severity:
Affected versions:
- Apache Thrift (thrift) before 0.24.0 - Apache Thrift (github.com/apache/thrift) before 0.24.0 - Apache Thrift (apache/thrift) before 0.24.0 - Apache Thrift (org.apache.thrift:libthrift) before 0.24.0
Description:
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Credit:
Yu Bao - yubao () paypal com, who works for paypal.com (finder)
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-43871
Severity: important
Affected versions:
- Apache Thrift (thrift) before 0.24.0
Description:
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
References:
https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-41608
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.