thrift
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting thriftpage 1 of 1
- CVE-2026-41608HIGHCVSS 7.5EG 7.5✓ Fixed in 0.24.02026-07-27
vulnerable: 0.10.0 ... 0.9.3 (17 versions)
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
- CVE-2026-43871HIGHCVSS 7.5EG 7.5✓ Fixed in 0.24.02026-07-27
vulnerable: 0.10.0 ... 0.9.3 (17 versions)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the i…
- CVE-2026-66053MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.24.02026-07-27
vulnerable: 0.10.0 ... 0.9.3 (17 versions)
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This repla…
Check whether thrift is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for thrift CVEs against the assets you own.
Start Free Scan →