Information on source package thrift

Available versions

ReleaseVersion
bullseye0.13.0-6
bookworm0.17.0-2
trixie0.19.0-4
forky0.23.0-3
sid0.23.0-3

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-66053vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-58662vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableImproper Validation of Specified Quantity in Input, Out-of-bounds Read ...
CVE-2026-58023vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableOut-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...
CVE-2026-55971vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableHeap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...
CVE-2026-55970vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableBuffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...
CVE-2026-55969vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableInteger Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...
CVE-2026-48586vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-48145vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-48144vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-45112vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-43871vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableLoop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...
CVE-2026-41608vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-41607vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...
CVE-2026-41606vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedUncontrolled Recursion vulnerability in Apache Thrift. This issue aff ...
CVE-2026-41602vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift TFramedT ...
CVE-2025-48431vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedMismatched Memory Management Routines vulnerability in Apache Thrift c ...
CVE-2020-13949vulnerable (no DSA, postponed)fixedfixedfixedfixedIn Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send sho ...

Open unimportant issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-58389vulnerablevulnerablevulnerablevulnerablevulnerableAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-55968vulnerablevulnerablevulnerablevulnerablevulnerableInefficient Algorithmic Complexity, Allocation of Resources Without Li ...
CVE-2026-49158vulnerablevulnerablevulnerablevulnerablevulnerableImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-43870vulnerablevulnerablevulnerablefixedfixedOrigin Validation Error, Improper Limitation of a Pathname to a Restri ...
CVE-2026-43869vulnerablevulnerablevulnerablefixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-43868vulnerablevulnerablevulnerablefixedfixedMemory Allocation with Excessive Size Value vulnerability in Apache Th ...
CVE-2026-41636vulnerablevulnerablevulnerablefixedfixedUncontrolled Recursion vulnerability in Apache Thrift Node.js bindings ...
CVE-2026-41605vulnerablevulnerablevulnerablefixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift. This i ...
CVE-2026-41604vulnerablevulnerablevulnerablefixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...

Resolved issues

BugDescription
CVE-2019-0210In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJS ...
CVE-2019-0205In Apache Thrift all versions up to and including 0.12.0, a server or ...
CVE-2018-11798The Apache Thrift Node.js static web server in versions 0.9.2 through ...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code ...

Search for package or bug name: Reporting problems