Information on source package thrift

Available versions

ReleaseVersion
bookworm0.17.0-2
trixie0.19.0-4
forky0.23.0-3
sid0.24.0-2

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-96289vulnerablevulnerablevulnerablevulnerableUncontrolled Recursion vulnerability in Apache Thrift PHP bindings. ...
CVE-2026-96287vulnerablevulnerablevulnerablevulnerableInefficient Algorithmic Complexity vulnerability in Apache Thrift Perl ...
CVE-2026-96286vulnerablevulnerablevulnerablevulnerableUncaught exception vulnerability in Apache Thrift Perl bindings. Th ...
CVE-2026-94654vulnerablevulnerablevulnerablevulnerableLoop with unreachable exit condition ('infinite loop') vulnerability i ...
CVE-2026-94653vulnerablevulnerablevulnerablevulnerableInefficient Algorithmic Complexity vulnerability in Apache Thrift PHP ...
CVE-2026-94652vulnerablevulnerablevulnerablevulnerableMissing release of memory after effective lifetime vulnerability in Ap ...
CVE-2026-94651vulnerablevulnerablevulnerablevulnerableimproper handling of exceptional conditions, Missing release of resour ...
CVE-2026-94650vulnerablevulnerablevulnerablevulnerableUncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. ...
CVE-2026-94644vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling vulnerability in ...
CVE-2026-94642vulnerablevulnerablevulnerablevulnerableUncaught exception vulnerability in Apache Thrift PHP bindings. Thi ...
CVE-2026-94639vulnerablevulnerablevulnerablevulnerableimproper handling of exceptional conditions, Allocation of resources w ...
CVE-2026-94638vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling vulnerability in ...
CVE-2026-94637vulnerablevulnerablevulnerablevulnerableImproper handling of highly compressed data (data amplification) vulne ...
CVE-2026-94636vulnerablevulnerablevulnerablevulnerableImproper handling of highly compressed data (data amplification), Func ...
CVE-2026-94634vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling, Initialization o ...
CVE-2026-93926vulnerablevulnerablevulnerablevulnerableMissing release of memory after effective lifetime, Missing release of ...
CVE-2026-93925vulnerablevulnerablevulnerablevulnerableStack-based buffer overflow, Incorrect bitwise shift of integer vulner ...
CVE-2026-92834vulnerablevulnerablevulnerablevulnerableUse of uninitialized resource, Return of wrong status code vulnerabili ...
CVE-2026-91137vulnerablevulnerablevulnerablevulnerableImproper validation of specified quantity in input, Allocation of reso ...
CVE-2026-91135vulnerablevulnerablevulnerablevulnerableHeap-based buffer overflow vulnerability in Apache Thrift C++ THeaderT ...
CVE-2026-85494vulnerablevulnerablevulnerablevulnerableImproper handling of length parameter inconsistency, Uncaught exceptio ...
CVE-2026-85483vulnerablevulnerablevulnerablevulnerableUse of uninitialized resource, Return of wrong status code vulnerabili ...
CVE-2026-85476vulnerablevulnerablevulnerablevulnerableLoop with unreachable exit condition ('infinite loop') vulnerability i ...
CVE-2026-85088vulnerablevulnerablevulnerablevulnerableImproper Validation of Certificate with Host Mismatch in the C++ and D ...
CVE-2026-85087vulnerablevulnerablevulnerablevulnerableImproper certificate validation, Return of wrong status code vulnerabi ...
CVE-2026-85086vulnerablevulnerablevulnerablevulnerableImproper certificate validation, Initialization of a resource with an ...
CVE-2026-83663vulnerablevulnerablevulnerablevulnerableUncontrolled Recursion vulnerability in Apache Thrift go bindings. ...
CVE-2026-83632vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling, Integer overflow ...
CVE-2026-82459vulnerablevulnerablevulnerablevulnerableInteger underflow (wrap or wraparound), Out-of-bounds write vulnerabil ...
CVE-2026-82458vulnerablevulnerablevulnerablevulnerableMemory allocation with excessive size value, Allocation of resources w ...
CVE-2026-66859vulnerablevulnerablevulnerablevulnerableNULL Pointer Dereference, Use of Uninitialized Variable vulnerability ...
CVE-2026-66858vulnerablevulnerablevulnerablevulnerableThe protocol skip routine in several Apache Thrift bindings did not ap ...
CVE-2026-66837vulnerablevulnerablevulnerablevulnerableStack-based Buffer Overflow, Integer Overflow or Wraparound vulnerabil ...
CVE-2026-66081vulnerablevulnerablevulnerablevulnerableAccess of Uninitialized Pointer vulnerability in Apache Thrift c_glib ...
CVE-2026-66055vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-66054vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling, Improper Handlin ...
CVE-2026-66053vulnerable (no DSA)vulnerable (no DSA)fixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-63772vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-61374vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-61373vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-58662vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Specified Quantity in Input, Out-of-bounds Read ...
CVE-2026-58023vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedOut-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...
CVE-2026-55971vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedHeap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...
CVE-2026-55970vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedBuffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...
CVE-2026-55969vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedInteger Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...
CVE-2026-48586vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-48145vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-48144vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-45112vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-43871vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedLoop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...
CVE-2026-41608vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-41607vulnerable (no DSA)vulnerable (no DSA)fixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...
CVE-2026-41606vulnerable (no DSA)vulnerable (no DSA)fixedfixedUncontrolled Recursion vulnerability in Apache Thrift. This issue aff ...
CVE-2026-41602vulnerable (no DSA)vulnerable (no DSA)fixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift TFramedT ...
CVE-2025-48431vulnerable (no DSA)vulnerable (no DSA)fixedfixedMismatched Memory Management Routines vulnerability in Apache Thrift c ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2026-96990vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-96294vulnerablevulnerablevulnerablevulnerableUncaught exception, Improper Handling of Exceptional Conditions vulner ...
CVE-2026-96292vulnerablevulnerablevulnerablevulnerableInefficient regular expression complexity, Inefficient Algorithmic Com ...
CVE-2026-96288vulnerablevulnerablevulnerablevulnerableUncontrolled Recursion, Allocation of resources without limits or thro ...
CVE-2026-96277vulnerablevulnerablevulnerablevulnerableUncaught exception, Improper Handling of Exceptional Conditions vulner ...
CVE-2026-94658vulnerablevulnerablevulnerablevulnerableInefficient Algorithmic Complexity vulnerability in Apache Thrift Lua ...
CVE-2026-94657vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling vulnerability in ...
CVE-2026-94656vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling vulnerability in ...
CVE-2026-94655vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling, Inefficient Algo ...
CVE-2026-94648vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling vulnerability in ...
CVE-2026-94646vulnerablevulnerablevulnerablevulnerableUncaught exception, Improper validation of specified quantity in input ...
CVE-2026-94645vulnerablevulnerablevulnerablevulnerableImproper validation of specified quantity in input, Allocation of reso ...
CVE-2026-94635vulnerablevulnerablevulnerablevulnerableAllocation of resources without limits or throttling, Improper handlin ...
CVE-2026-94633vulnerablevulnerablevulnerablevulnerableMemory allocation with excessive size value, Improper handling of leng ...
CVE-2026-90440vulnerablevulnerablevulnerablevulnerableUncaught exception, improper handling of exceptional conditions, impro ...
CVE-2026-87117vulnerablevulnerablevulnerablevulnerableNULL pointer dereference vulnerability in Apache Thrift PHP bindings. ...
CVE-2026-86537vulnerablevulnerablevulnerablevulnerableUncaught exception, Loop with unreachable exit condition ('infinite lo ...
CVE-2026-86536vulnerablevulnerablevulnerablevulnerableImproperly controlled modification of object prototype attributes ('pr ...
CVE-2026-86535vulnerablevulnerablevulnerablevulnerableLoop with unreachable exit condition ('infinite loop'), Improperly con ...
CVE-2026-85493vulnerablevulnerablevulnerablevulnerableUncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME ...
CVE-2026-83745vulnerablevulnerablevulnerablevulnerableMemory allocation with excessive size value, Improper handling of leng ...
CVE-2026-66331vulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-58389vulnerablevulnerablevulnerablefixedAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-55968vulnerablevulnerablevulnerablefixedInefficient Algorithmic Complexity, Allocation of Resources Without Li ...
CVE-2026-49158vulnerablevulnerablevulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-43870vulnerablevulnerablefixedfixedOrigin Validation Error, Improper Limitation of a Pathname to a Restri ...
CVE-2026-43869vulnerablevulnerablefixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-43868vulnerablevulnerablefixedfixedMemory Allocation with Excessive Size Value vulnerability in Apache Th ...
CVE-2026-41636vulnerablevulnerablefixedfixedUncontrolled Recursion vulnerability in Apache Thrift Node.js bindings ...
CVE-2026-41605vulnerablevulnerablefixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift. This i ...
CVE-2026-41604vulnerablevulnerablefixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...

Resolved issues

BugDescription
CVE-2020-13949In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send sho ...
CVE-2019-0210In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJS ...
CVE-2019-0205In Apache Thrift all versions up to and including 0.12.0, a server or ...
CVE-2018-11798The Apache Thrift Node.js static web server in versions 0.9.2 through ...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code ...

Search for package or bug name: Reporting problems