github.com/apache/thrift
Apache Thrift
Activity
- Latest release
- 2mo ago
- Total releases
- 16
- Cadence
- ~6 months
- Last 12 months
- 2
Reach
- Stars
- 10.9k
Details
- First release
- Dec 19, 2018
| Version | Released | |
|---|---|---|
v0.24.0
minor
|
v0.24.0
minor
|
|
v0.23.0
minor
1 CVE
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.0
minor
|
|
v0.22.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.0
minor
|
|
v0.21.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.21.0
minor
|
|
v0.20.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.20.0
minor
|
|
v0.19.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.19.0
minor
|
|
v0.18.1
patch
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.18.1
patch
|
|
v0.18.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.18.0
minor
|
|
v0.17.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (1)
|
|
v0.16.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (1)
|
|
v0.15.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.15.0
minor
Dependencies (1)
|
|
v0.14.2
patch
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.14.2
patch
|
|
v0.14.1
patch
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.14.1
patch
|
|
v0.14.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.14.0
minor
|
|
v0.13.0
minor
2 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.13.0
minor
|
|
v0.12.0
initial
3 CVEs
CVE-2026-43871
GHSA-8wv5-x4w7-5gww
BIT-thrift-2026-43871
PYSEC-2026-3926
Jul 27, 2026
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
High
Network
Low
None
None
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Fixed in
0.24.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-41602
GHSA-wf45-q9ch-q8gh
BIT-thrift-2026-41602
Apr 28, 2026
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Fixed in
0.23.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-0210
GO-2021-0101
GHSA-jq7p-26h5-w78r
Jul 28, 2021
Panic due to out-of-bounds read in github.com/apache/thrift Due to an improper bounds check, parsing maliciously crafted messages can cause panics. If this package is used to parse untrusted input, this may be used as a vector for a denial of service attack. Fixed in
0.13.0
Updated Jun 16, 2026 · Source: OSV.dev |
v0.12.0
initial
|