org.apache.thrift:libthrift
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.thrift:libthriftpage 1 of 1
- CVE-2018-11798MEDIUMCVSS 6.5EG 6.5fixed in 0.12.02019-01-07
vulnerable: 0.10.0, 0.11.0, 0.9.2, 0.9.3, 0.9.3-1
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
- CVE-2018-1320HIGHCVSS 7.5EG 7.5fixed in 0.9.3-1 or 0.12.0, by version range2019-01-07
vulnerable: 0.10.0, 0.11.0
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully c…
- CVE-2019-0205HIGHCVSS 7.5EG 7.5fixed in 0.13.02019-10-29
vulnerable: 0.10.0 ... 0.9.3-1 (11 versions)
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed …
- CVE-2020-13949HIGHCVSS 7.5EG 7.5fixed in 0.14.02021-02-12
vulnerable: 0.10.0 ... 0.9.3-1 (6 versions)
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
- CVE-2026-43869HIGHCVSS 7.3EG 7.3fixed in 0.23.02026-05-05
vulnerable: 0.10.0 ... 0.9.3-1 (24 versions)
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
- CVE-2026-43871HIGHCVSS 7.5EG 7.5fixed in 0.24.02026-07-27
vulnerable: 0.10.0 ... 0.9.3-1 (25 versions)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the i…
Check whether org.apache.thrift:libthrift is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.thrift:libthrift CVEs against the assets you own.
Book a Demo →