This page lists publicly disclosed CVE vulnerabilities affecting apache thrift (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-43870 | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | [email protected] | 7.3 | 0.39% | 2026-05-05 | 2026-05-06 |
| CVE-2026-43868 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | [email protected] | 5.3 | 0.38% | 2026-05-05 | 2026-05-06 |
| CVE-2026-43869 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | [email protected] | 7.3 | 0.29% | 2026-05-05 | 2026-05-06 |
| CVE-2020-13949 | In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. | [email protected] | 7.5 | 6.78% | 2021-02-12 | 2024-11-21 |
| CVE-2019-0210 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. | [email protected] | 7.5 | 6.79% | 2019-10-29 | 2024-11-21 |
| CVE-2019-0205 | In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. | [email protected] | 7.5 | 9.08% | 2019-10-29 | 2024-11-21 |
| CVE-2018-1320 | Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete. | [email protected] | 7.5 | 8.19% | 2019-01-07 | 2024-11-21 |
| CVE-2018-11798 | The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path. | [email protected] | 6.5 | 4.88% | 2019-01-07 | 2024-11-21 |
| CVE-2016-5397 | The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0. | [email protected] | 8.8 | 7.32% | 2018-02-12 | 2024-11-21 |
| CVE-2015-3254 | The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function. | [email protected] | 6.5 | 5.33% | 2017-06-16 | 2026-05-13 |