Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/github.com/apache/thrift

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-66054 is a vulnerability in Apache Thrift C++ bindings involving allocation of resources without limits or throttling, leading to improper handling of highly compressed data (data amplification). This affects versions before 0.25.0. The issue is fixed in version 0.25.0. The vulnerability has a CVSS 4.0 base score of 6.9, indicating medium severity.

Join the discussion

CVE-2026-63772 is a high-severity vulnerability in Apache Thrift's Go bindings involving allocation of resources without limits or throttling. It affects versions before 0.25.0. The issue can lead to resource exhaustion due to uncontrolled allocation. Apache has fixed this vulnerability in version 0.25.0, and users are advised to upgrade to this version to mitigate the risk.

Join the discussion

CVE-2026-66055 is a high-severity vulnerability in Apache Thrift affecting C++, Java, Go, netstd, Python, and Delphi bindings. It involves allocation of resources without limits or throttling, potentially leading to resource exhaustion. The issue affects all versions before 0.25.0. The Apache Software Foundation has fixed this vulnerability in version 0.25.0. Users are advised to upgrade to this version to mitigate the risk.

Join the discussion

CVE-2026-66081 is a high-severity vulnerability in Apache Thrift's c_glib bindings involving access of an uninitialized pointer. This flaw affects all versions before 0.25.0. The issue is addressed by upgrading to version 0.25.0, which contains the fix.

Join the discussion

CVE-2026-66331 is a resource allocation vulnerability in Apache Thrift's Delphi bindings buffered transport. It affects versions before 0.25.0. The issue involves allocation of resources without limits or throttling, which could lead to resource exhaustion. The Apache Software Foundation has fixed this issue in version 0.25.0. The vulnerability has a medium severity with a CVSS score of 6.9.

Join the discussion

CVE-2026-66859 is a high-severity vulnerability in Apache Thrift's c_glib bindings involving NULL pointer dereference and use of uninitialized variables. This flaw affects all versions prior to 0.25.0. The issue can lead to application crashes or undefined behavior. The Apache Software Foundation has fixed this vulnerability in version 0.25.0. Users are advised to upgrade to this version to remediate the issue.

Join the discussion

CVE-2026-83632 is a critical vulnerability in Apache Thrift before version 0.25.0 involving allocation of resources without limits or throttling, integer overflow or wraparound, and a heap-based buffer overflow. This flaw can lead to severe impacts on system stability and security. The issue is resolved in Apache Thrift version 0.25.0.

Join the discussion

CVE-2026-83663 is an uncontrolled recursion vulnerability in the Go bindings of Apache Thrift before version 0.25.0. The issue arises when the Go transports read a buffered frame yielding no payload bytes and recursively call Read again without looping, leading to unbounded recursion. This causes the Go stack limit to be reached, resulting in a fatal error that terminates the process. The vulnerability is fixed in Apache Thrift version 0.25.0.

Join the discussion

CVE-2026-85476 is a high-severity vulnerability in Apache Thrift's c_glib bindings involving a loop with an unreachable exit condition, effectively causing an infinite loop. This issue affects versions before 0.25.0. The vulnerability is fixed in Apache Thrift version 0.25.0. Users are advised to upgrade to this version to remediate the issue.

Join the discussion

CVE-2026-94658 is a high-severity vulnerability in Apache Thrift affecting versions before 0.25.0. It involves an inefficient algorithmic complexity issue in the Lua bindings of Apache Thrift. This flaw can lead to performance degradation or denial of service due to resource exhaustion. The Apache Software Foundation has fixed this issue in version 0.25.0.

Join the discussion

Showing 1 to 10 of 29 results

Filters:Package: pkg:github/github.com/apache/thrift
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses