Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: thrift

Found 10 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-55971
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-58389
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: Rust binary protocol non-strict path missing string size limit

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-55969
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

Delphi
  • <0.24.0
thrift
  • <0.24.0
ApacheThrift
  • <0.24.0
c_glib language bindings
  • <0.24.0
github.com/apache/thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-58662
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-55970
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-66053
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: Python TSSLSocket Hostname Matcher Import

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-48586
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

c_glib
  • <0.24.0
thrift
  • <0.24.0
D language
  • <0.24.0
github.com/apache/thrift
  • <0.24.0
org.apache.thrift:libthrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-48145
8.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers

Permalink CVE-2026-43871
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 1 week, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • fbthrift
    • thrift-ls
    • rubyPackages.thrift
    • rubyPackages_3_3.thrift
    • rubyPackages_3_4.thrift
    • rubyPackages_4_0.thrift
    • akkuPackages.r6rs-thrift
    • python313Packages.thrift
    • python314Packages.thrift
    • python313Packages.thriftpy2
    • python314Packages.thriftpy2
    • tree-sitter-grammars.tree-sitter-thrift
    • vimPlugins.nvim-treesitter-parsers.thrift
    • python313Packages.tree-sitter-grammars.tree-sitter-thrift
    • python314Packages.tree-sitter-grammars.tree-sitter-thrift
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

thrift
  • <0.24.0
apache/thrift
  • <0.24.0
github.com/apache/thrift
  • <0.24.0
org.apache.thrift:libthrift
  • <0.24.0

Matching in nixpkgs

Ignored packages (15)

Package maintainers