org.apache.thrift:libthrift
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.thrift:libthriftpage 1 of 1
- CVE-2018-11798MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.12.02019-01-07
vulnerable: 0.10.0, 0.11.0, 0.9.2, 0.9.3, 0.9.3-1
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
- CVE-2018-1320HIGHCVSS 7.5EG 7.5✓ Fixed in 0.12.02019-01-07
vulnerable: 0.10.0, 0.11.0
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully c…
- CVE-2019-0205HIGHCVSS 7.5EG 7.5✓ Fixed in 0.13.02019-10-29
vulnerable: 0.10.0 ... 0.9.3-1 (11 versions)
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed …
- CVE-2020-13949HIGHCVSS 7.5EG 7.5✓ Fixed in 0.14.02021-02-12
vulnerable: 0.10.0 ... 0.9.3-1 (6 versions)
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
- CVE-2026-43869HIGHCVSS 7.3EG 7.32026-05-05
vulnerable: 0.10.0 ... 0.9.3-1 (24 versions)
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Check whether org.apache.thrift:libthrift is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.thrift:libthrift CVEs against the assets you own.
Start Free Scan →