Information on source package thrift

Available versions

ReleaseVersion
bookworm0.17.0-2
trixie0.19.0-4
forky0.23.0-3
sid0.24.0-2

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-66053vulnerable (no DSA)vulnerable (no DSA)fixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-58662vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Specified Quantity in Input, Out-of-bounds Read ...
CVE-2026-58023vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedOut-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...
CVE-2026-55971vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedHeap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...
CVE-2026-55970vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedBuffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...
CVE-2026-55969vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedInteger Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...
CVE-2026-48586vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-48145vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-48144vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-45112vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-43871vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedLoop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...
CVE-2026-41608vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-41607vulnerable (no DSA)vulnerable (no DSA)fixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...
CVE-2026-41606vulnerable (no DSA)vulnerable (no DSA)fixedfixedUncontrolled Recursion vulnerability in Apache Thrift. This issue aff ...
CVE-2026-41602vulnerable (no DSA)vulnerable (no DSA)fixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift TFramedT ...
CVE-2025-48431vulnerable (no DSA)vulnerable (no DSA)fixedfixedMismatched Memory Management Routines vulnerability in Apache Thrift c ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2026-58389vulnerablevulnerablevulnerablefixedAllocation of Resources Without Limits or Throttling vulnerability in ...
CVE-2026-55968vulnerablevulnerablevulnerablefixedInefficient Algorithmic Complexity, Allocation of Resources Without Li ...
CVE-2026-49158vulnerablevulnerablevulnerablefixedImproper Handling of Highly Compressed Data (Data Amplification) vulne ...
CVE-2026-43870vulnerablevulnerablefixedfixedOrigin Validation Error, Improper Limitation of a Pathname to a Restri ...
CVE-2026-43869vulnerablevulnerablefixedfixedImproper Validation of Certificate with Host Mismatch vulnerability in ...
CVE-2026-43868vulnerablevulnerablefixedfixedMemory Allocation with Excessive Size Value vulnerability in Apache Th ...
CVE-2026-41636vulnerablevulnerablefixedfixedUncontrolled Recursion vulnerability in Apache Thrift Node.js bindings ...
CVE-2026-41605vulnerablevulnerablefixedfixedInteger Overflow or Wraparound vulnerability in Apache Thrift. This i ...
CVE-2026-41604vulnerablevulnerablefixedfixedOut-of-bounds Read vulnerability in Apache Thrift. This issue affects ...

Resolved issues

BugDescription
CVE-2020-13949In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send sho ...
CVE-2019-0210In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJS ...
CVE-2019-0205In Apache Thrift all versions up to and including 0.12.0, a server or ...
CVE-2018-11798The Apache Thrift Node.js static web server in versions 0.9.2 through ...
CVE-2016-5397The Apache Thrift Go client library exposed the potential during code ...

Search for package or bug name: Reporting problems