logo

Critical Flaws in Apache Thrift Threaten Multi-Language

ID: ba2b7978-ab09-5748-9594-9f51220f9499

STIX ID: report--ba2b7978-ab09-5748-9594-9f51220f9499

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Ddos

...
...

Apache Thrift released an urgent 0.23.0 update addressing three security flaws across its Rust, Java, and Node.js implementations: a memory-allocation exhaustion leading to DoS, a Java TLS hostname verification failure that can enable Man-in-the-Middle interception, and a multi-vulnerability issue in Node.js (path traversal, HTTP splitting, origin validation errors, and resource exhaustion). Organizations using Thrift should upgrade immediately and audit multi-language service dependencies to mitigate cascading risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.