{"schema_version":1,"title":"Apache Thrift vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Apache Thrift: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-66053, was published on 27 July 2026.","url":"https://junglewise.ai/threats/technologies/thrift","json_url":"https://junglewise.ai/threats/technologies/thrift.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/thrift","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":16},"latest":[{"cve":"CVE-2026-66053","cvss":5.9,"epss":0.0029,"slug":"cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings","title":"Apache Thrift certificate validation bypass in Python bindings","severity":"medium","exploited":false,"published_at":"2026-07-27T12:16:55.027+00:00","url":"https://junglewise.ai/threats/cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings"},{"cve":"CVE-2026-58023","cvss":6.9,"slug":"cve-2026-58023-apache-thrift-out-of-bounds-read-in-c-glib-bindings","title":"Apache Thrift out-of-bounds read in c_glib bindings","severity":"info","exploited":false,"published_at":"2026-07-27T12:16:46.547+00:00","url":"https://junglewise.ai/threats/cve-2026-58023-apache-thrift-out-of-bounds-read-in-c-glib-bindings"},{"cve":"CVE-2026-55970","cvss":6.9,"slug":"cve-2026-55970-apache-thrift-buffer-over-read-in-c-bindings","title":"Apache Thrift buffer over-read in C++ bindings","severity":"info","exploited":false,"published_at":"2026-07-27T12:16:45.977+00:00","url":"https://junglewise.ai/threats/cve-2026-55970-apache-thrift-buffer-over-read-in-c-bindings"},{"cve":"CVE-2026-43871","cvss":7.5,"epss":0.0103,"slug":"cve-2026-43871-apache-thrift-infinite-loop-in-python-go-php-and-java-bindings","title":"Apache Thrift infinite loop in Python, Go, PHP and Java bindings","severity":"high","exploited":false,"published_at":"2026-07-27T12:16:44.413+00:00","url":"https://junglewise.ai/threats/cve-2026-43871-apache-thrift-infinite-loop-in-python-go-php-and-java-bindings"},{"cve":"CVE-2026-41608","cvss":7.5,"epss":0.0103,"slug":"cve-2026-41608-apache-thrift-data-amplification-in-python-theadertransport","title":"Apache Thrift data amplification in Python THeaderTransport","severity":"high","exploited":false,"published_at":"2026-07-27T12:16:44.277+00:00","url":"https://junglewise.ai/threats/cve-2026-41608-apache-thrift-data-amplification-in-python-theadertransport"},{"cve":"CVE-2026-43870","cvss":3.1,"epss":0.0038,"slug":"cve-2026-43870-apache-thrift-path-traversal-and-request-splitting-in-web-server","title":"Apache Thrift path traversal and request splitting in web server","severity":"low","exploited":false,"published_at":"2026-05-05T09:31:55+00:00","url":"https://junglewise.ai/threats/cve-2026-43870-apache-thrift-path-traversal-and-request-splitting-in-web-server"},{"cve":"CVE-2026-43868","cvss":5.3,"epss":0.012,"slug":"cve-2026-43868-apache-thrift-denial-of-service-via-excessive-memory-allocation","title":"Apache Thrift denial of service via excessive memory allocation","severity":"medium","exploited":false,"published_at":"2026-05-05T09:16:04.123+00:00","url":"https://junglewise.ai/threats/cve-2026-43868-apache-thrift-denial-of-service-via-excessive-memory-allocation"},{"cve":"CVE-2026-43869","cvss":7.3,"epss":0.0081,"slug":"cve-2026-43869-apache-thrift-improper-certificate-validation-in","title":"Apache Thrift improper certificate validation in TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-05-05T08:16:01.063+00:00","url":"https://junglewise.ai/threats/cve-2026-43869-apache-thrift-improper-certificate-validation-in"},{"cve":"CVE-2026-41636","cvss":4,"epss":0.0073,"slug":"cve-2026-41636-apache-thrift-node-js-bindings-uncontrolled-recursion","title":"Apache Thrift Node.js bindings uncontrolled recursion","severity":"medium","exploited":false,"published_at":"2026-04-28T12:31:30+00:00","url":"https://junglewise.ai/threats/cve-2026-41636-apache-thrift-node-js-bindings-uncontrolled-recursion"},{"cve":"CVE-2026-41607","cvss":6.5,"epss":0.0051,"slug":"cve-2026-41607-apache-thrift-out-of-bounds-read-in-c-json-implementation","title":"Apache Thrift out-of-bounds read in C++ JSON implementation","severity":"medium","exploited":false,"published_at":"2026-04-28T10:16:03.573+00:00","url":"https://junglewise.ai/threats/cve-2026-41607-apache-thrift-out-of-bounds-read-in-c-json-implementation"},{"cve":"CVE-2026-41606","cvss":5.3,"epss":0.0059,"slug":"cve-2026-41606-apache-thrift-uncontrolled-recursion-in-c-glib-dispatch","title":"Apache Thrift uncontrolled recursion in c_glib dispatch","severity":"medium","exploited":false,"published_at":"2026-04-28T10:16:03.463+00:00","url":"https://junglewise.ai/threats/cve-2026-41606-apache-thrift-uncontrolled-recursion-in-c-glib-dispatch"},{"cve":"CVE-2026-41605","cvss":7.3,"epss":0.0054,"slug":"cve-2026-41605-apache-thrift-integer-overflow-in-swift-compact-protocol","title":"Apache Thrift integer overflow in Swift Compact Protocol","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.35+00:00","url":"https://junglewise.ai/threats/cve-2026-41605-apache-thrift-integer-overflow-in-swift-compact-protocol"},{"cve":"CVE-2026-41604","cvss":8.2,"epss":0.0058,"slug":"cve-2026-41604-apache-thrift-out-of-bounds-read-in-swift-range-skip-function","title":"Apache Thrift out-of-bounds read in Swift Range skip function","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.23+00:00","url":"https://junglewise.ai/threats/cve-2026-41604-apache-thrift-out-of-bounds-read-in-swift-range-skip-function"},{"cve":"CVE-2026-41603","cvss":7.4,"epss":0.0025,"slug":"cve-2026-41603-apache-thrift-improper-certificate-validation-in-java","title":"Apache Thrift improper certificate validation in Java TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.113+00:00","url":"https://junglewise.ai/threats/cve-2026-41603-apache-thrift-improper-certificate-validation-in-java"},{"cve":"CVE-2026-41602","cvss":7.5,"epss":0.0138,"slug":"cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport","title":"Apache Thrift integer overflow in Go TFramedTransport","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03+00:00","url":"https://junglewise.ai/threats/cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport"},{"cve":"CVE-2025-48431","cvss":7.5,"epss":0.0066,"slug":"cve-2025-48431-apache-thrift-denial-of-service-in-c-glib-language-bindings","title":"Apache Thrift denial of service in c_glib language bindings","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:02.153+00:00","url":"https://junglewise.ai/threats/cve-2025-48431-apache-thrift-denial-of-service-in-c-glib-language-bindings"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache Thrift","slug":"thrift","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"library","homepage":"https://thrift.apache.org/","description":"A software framework for cross-language RPC and data serialization.","url":"https://junglewise.ai/threats/technologies/thrift"},"most_severe":[{"cve":"CVE-2026-41604","cvss":8.2,"epss":0.0058,"slug":"cve-2026-41604-apache-thrift-out-of-bounds-read-in-swift-range-skip-function","title":"Apache Thrift out-of-bounds read in Swift Range skip function","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.23+00:00","url":"https://junglewise.ai/threats/cve-2026-41604-apache-thrift-out-of-bounds-read-in-swift-range-skip-function"},{"cve":"CVE-2026-41602","cvss":7.5,"epss":0.0138,"slug":"cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport","title":"Apache Thrift integer overflow in Go TFramedTransport","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03+00:00","url":"https://junglewise.ai/threats/cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport"},{"cve":"CVE-2026-43871","cvss":7.5,"epss":0.0103,"slug":"cve-2026-43871-apache-thrift-infinite-loop-in-python-go-php-and-java-bindings","title":"Apache Thrift infinite loop in Python, Go, PHP and Java bindings","severity":"high","exploited":false,"published_at":"2026-07-27T12:16:44.413+00:00","url":"https://junglewise.ai/threats/cve-2026-43871-apache-thrift-infinite-loop-in-python-go-php-and-java-bindings"},{"cve":"CVE-2026-41608","cvss":7.5,"epss":0.0103,"slug":"cve-2026-41608-apache-thrift-data-amplification-in-python-theadertransport","title":"Apache Thrift data amplification in Python THeaderTransport","severity":"high","exploited":false,"published_at":"2026-07-27T12:16:44.277+00:00","url":"https://junglewise.ai/threats/cve-2026-41608-apache-thrift-data-amplification-in-python-theadertransport"},{"cve":"CVE-2025-48431","cvss":7.5,"epss":0.0066,"slug":"cve-2025-48431-apache-thrift-denial-of-service-in-c-glib-language-bindings","title":"Apache Thrift denial of service in c_glib language bindings","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:02.153+00:00","url":"https://junglewise.ai/threats/cve-2025-48431-apache-thrift-denial-of-service-in-c-glib-language-bindings"},{"cve":"CVE-2026-41603","cvss":7.4,"epss":0.0025,"slug":"cve-2026-41603-apache-thrift-improper-certificate-validation-in-java","title":"Apache Thrift improper certificate validation in Java TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.113+00:00","url":"https://junglewise.ai/threats/cve-2026-41603-apache-thrift-improper-certificate-validation-in-java"},{"cve":"CVE-2026-43869","cvss":7.3,"epss":0.0081,"slug":"cve-2026-43869-apache-thrift-improper-certificate-validation-in","title":"Apache Thrift improper certificate validation in TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-05-05T08:16:01.063+00:00","url":"https://junglewise.ai/threats/cve-2026-43869-apache-thrift-improper-certificate-validation-in"},{"cve":"CVE-2026-41605","cvss":7.3,"epss":0.0054,"slug":"cve-2026-41605-apache-thrift-integer-overflow-in-swift-compact-protocol","title":"Apache Thrift integer overflow in Swift Compact Protocol","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.35+00:00","url":"https://junglewise.ai/threats/cve-2026-41605-apache-thrift-integer-overflow-in-swift-compact-protocol"},{"cve":"CVE-2026-41607","cvss":6.5,"epss":0.0051,"slug":"cve-2026-41607-apache-thrift-out-of-bounds-read-in-c-json-implementation","title":"Apache Thrift out-of-bounds read in C++ JSON implementation","severity":"medium","exploited":false,"published_at":"2026-04-28T10:16:03.573+00:00","url":"https://junglewise.ai/threats/cve-2026-41607-apache-thrift-out-of-bounds-read-in-c-json-implementation"},{"cve":"CVE-2026-66053","cvss":5.9,"epss":0.0029,"slug":"cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings","title":"Apache Thrift certificate validation bypass in Python bindings","severity":"medium","exploited":false,"published_at":"2026-07-27T12:16:55.027+00:00","url":"https://junglewise.ai/threats/cve-2026-66053-apache-thrift-certificate-validation-bypass-in-python-bindings"}],"generated_at":"2026-09-26T20:07:00.238639+00:00"}