Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Apache Thrift | 27/7/2026 | 28/7/2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | |
| Analizada | Alta (7.3) | 0.38% | — | Apache Thrift | 5/5/2026 | 17/6/2026 | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.… | |
| Modificada | Media (5.3) | 1.2% | — | Apache Thrift | 5/5/2026 | 21/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.3) | 0.81% | — | Apache Thrift | 5/5/2026 | 9/9/2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Analizada | Alta (8.7) | 0.73% | — | Apache Thrift | 28/4/2026 | 17/6/2026 | Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Media (6.5) | 0.90% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Media (5.3) | 1.1% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.3) | 1.3% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (8.2) | 1.2% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.5) | 1.4% | — | Apache Thrift | 28/4/2026 | 9/9/2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Modificada | Alta (7.5) | 0.71% | — | Apache Thrift | 28/4/2026 | 7/10/2026 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but… | |
| Aplazada | Media (5.3) | 0.35% | — | Facebook ThriftAI | 27/9/2024 | 17/6/2026 | A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00. | |
| Aplazada | Alta (7.5) | 0.48% | — | Facebook ThriftAI | 27/9/2024 | 17/6/2026 | A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00. | |
| Modificada | Crítica (9.8) | 1.7% | — | Facebook Thrift | 14/4/2021 | 17/6/2026 | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00. | |
| Modificada | Alta (7.5) | 6.8% | — | Apache HiveApache ThriftOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core Policy | 12/2/2021 | 17/6/2026 | In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | Facebook Thrift | 18/3/2020 | 17/6/2026 | Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 2.1% | — | Facebook Thrift | 10/3/2020 | 17/6/2026 | C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 2.3% | — | Facebook Thrift | 10/3/2020 | 17/6/2026 | Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 6.4% | — | Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function | 29/10/2019 | 17/6/2026 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. | |
| Modificada | Alta (7.5) | 9.2% | — | Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function | 29/10/2019 | 17/6/2026 | In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. | |
| Modificada | Alta (7.5) | 2.8% | — | Facebook Thrift | 6/5/2019 | 17/6/2026 | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects… | |
| Modificada | Alta (7.5) | 2.0% | — | Facebook Thrift | 6/5/2019 | 17/6/2026 | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 2.0% | — | Facebook Thrift | 6/5/2019 | 17/6/2026 | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 2.0% | — | Facebook Thrift | 6/5/2019 | 17/6/2026 | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to… | |
| Modificada | Alta (7.5) | 2.0% | — | Facebook Thrift | 6/5/2019 | 17/6/2026 | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior… |