Where
-Infinity
0

Apache ThriftAllocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. …

Risk 33
Severity
7
First published (updated )

Apache Thrift (Python bindings)Apache Thrift: Python TSSLSocket Hostname Matcher Import

Risk 38
Severity
5.9
First published (updated )

Apache ThriftApache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass

Risk 70
Severity
8.7
First published (updated )

Apache Apache ThriftApache Thrift: Rust binary protocol non-strict path missing string size limit

Risk 50
Severity
8.7
First published (updated )

Apache Thrift (C++ bindings)Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

Risk 91
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Apache ThriftApache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path

Risk 70
Severity
6.9
First published (updated )

Apache ThriftApache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()

Risk 44
Severity
6.9
First published (updated )

Apache ThriftApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

Risk 50
Severity
8.7
First published (updated )

Apache Apache ThriftApache Thrift: Node.js quadratic-time DoS in server receive transports

Risk 50
Severity
8.7
First published (updated )

Apache ThriftApache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache ThriftApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit

Risk 51
Severity
8.7
First published (updated )

Apache Thrift (C++ bindings)Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

Risk 46
Severity
8.2
First published (updated )

Apache Apache ThriftApache Thrift: c_glib TLS Client Missing Hostname Verification

Risk 67
Severity
9.1
First published (updated )

Apache Thrift Java bindingsApache Thrift: Unbounded Read Leading to Denial of Service

Risk 46
Severity
6.9
First published (updated )

Apache ThriftApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

Risk 50
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Apache ThriftApache Thrift: Unbounded Zlib Decompression in Python THeaderTransport

Risk 46
Severity
7.5
First published (updated )

oss-secCVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import

oss-secCVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit

oss-secCVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds ad in transport leftover-bytes path

oss-secCVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-55970: Apache Thrift: C++ heap out-of-bounds ad in THeaderTransport::adHeaderFormat()

oss-secCVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server ceive transports

oss-secCVE-2026-48586: Apache Thrift: TZlibTransport Decompssion Size Limit

oss-secCVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

oss-secCVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit

oss-secCVE-2026-41608: Apache Thrift: Unbounded Zlib Decompssion in Python THeaderTransport

Apache ThriftMemory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apac…

Risk 33
Severity
7
First published (updated )

Apache ThriftPath Traversal

Risk 33
Severity
7
First published (updated )

Apache ThriftImproper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue af…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203