Information on source package thrift

Available versions

ReleaseVersion
bullseye0.13.0-6
bookworm0.17.0-2
trixie0.19.0-4
forky0.23.0-3
sid0.23.0-3

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-41607vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...
CVE-2026-41606vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedUncontrolled Recursion vulnerability in Apache Thrift. This issue aff ...
CVE-2026-41603vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-41602vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift TFramedT ...
CVE-2025-48431vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedMismatched Memory Management Routines vulnerability in Apache Thrift c ...
CVE-2020-13949vulnerable (no DSA, postponed)fixedfixedfixedfixedIn Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send sho ...

Open unimportant issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-43870vulnerablevulnerablevulnerablefixedfixedOrigin Validation Error, Improper Limitation of a Pathname to a Restri ...
CVE-2026-43869vulnerablevulnerablevulnerablefixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-43868vulnerablevulnerablevulnerablefixedfixedMemory Allocation with Excessive Size Value vulnerability in Apache Th ...
CVE-2026-41636vulnerablevulnerablevulnerablefixedfixedUncontrolled Recursion vulnerability in Apache Thrift Node.js bindings ...
CVE-2026-41605vulnerablevulnerablevulnerablefixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift. This i ...
CVE-2026-41604vulnerablevulnerablevulnerablefixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...

Resolved issues

BugDescription
CVE-2019-0210In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJS ...
CVE-2019-0205In Apache Thrift all versions up to and including 0.12.0, a server or ...
CVE-2018-11798The Apache Thrift Node.js static web server in versions 0.9.2 through ...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code ...

Search for package or bug name: Reporting problems