Apache
Apache Thrift: vulnerabilidades y CVE
Apache Thrift tiene 93 vulnerabilidades publicadas, 86 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE93
Últimos 12 meses86
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96289 | Alta (8.2) | — | — | 2 oct 2026 | Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-96287 | Alta (8.2) | — | — | 2 oct 2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-96286 | Alta (8.2) | — | — | 2 oct 2026 | Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-96277 | Alta (8.7) | — | — | 2 oct 2026 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… |
| CVE-2026-94658 | Alta (8.7) | — | — | 2 oct 2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-94657 | Alta (8.2) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-94656 | Alta (8.2) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-94655 | Alta (8.2) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to… |
| CVE-2026-94654 | Alta (8.2) | — | — | 2 oct 2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-85476 | Alta (8.2) | — | — | 2 oct 2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-83745 | Alta (8.7) | — | — | 2 oct 2026 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload… |
| CVE-2026-83663 | Alta (8.7) | — | — | 2 oct 2026 | Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again… |
| CVE-2026-83632 | Crítica (9.2) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to… |
| CVE-2026-66859 | Alta (8.7) | — | — | 2 oct 2026 | NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes… |
| CVE-2026-66858 | Alta (8.7) | — | — | 2 oct 2026 | The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator… |
| CVE-2026-66837 | Alta (8.7) | — | — | 2 oct 2026 | Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes… |
| CVE-2026-66331 | Media (6.9) | — | — | 2 oct 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version… |
| CVE-2026-66081 | Alta (8.7) | — | — | 2 oct 2026 | Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-66055 | Alta (8.2) | — | — | 2 oct 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to… |
| CVE-2026-66054 | Media (6.9) | — | — | 2 oct 2026 | Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users… |
| CVE-2026-63772 | Alta (8.7) | — | — | 2 oct 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-61374 | Alta (7.1) | — | — | 2 oct 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-96294 | Alta (8.7) | — | — | 2 oct 2026 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which… |
| CVE-2026-96292 | Alta (8.2) | — | — | 2 oct 2026 | Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version… |
| CVE-2026-96288 | Alta (8.2) | — | — | 2 oct 2026 | Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version… |
| CVE-2026-94653 | Alta (8.2) | — | — | 2 oct 2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-94652 | Media (6.3) | — | — | 2 oct 2026 | Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-94648 | Alta (8.2) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
| CVE-2026-94646 | Alta (8.7) | — | — | 2 oct 2026 | Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This… |
| CVE-2026-94638 | Media (6.3) | — | — | 2 oct 2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.