| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Thrift | < 0.24.0 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Thrift | 0 ~ 0.24.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55971 | 9.3 CRITICAL | Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() |
| CVE-2026-48144 | 9.1 CRITICAL | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-58662 | 8.7 HIGH | Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass |
| CVE-2026-58389 | 8.7 HIGH | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-55969 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: |
| CVE-2026-55968 | 8.7 HIGH | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-48586 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: |
| CVE-2026-43871 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-c |
| CVE-2026-48145 | 8.2 HIGH | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-49158 | 7.5 HIGH | Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb |
| CVE-2026-55970 | 6.9 MEDIUM | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() |
| CVE-2026-45112 | 6.9 MEDIUM | Apache Thrift: Unbounded Read Leading to Denial of Service |
| CVE-2026-66053 | 5.9 MEDIUM | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-66391 | Apache Wicket: leaked and missing CSP headers | |
| CVE-2026-66390 | Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence | |
| CVE-2026-41608 | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport |
No comments yet