« List of all CVEs

CVE-2020-13949

Published: 2/12/2021 Last updated: 8/4/2024 Reserved: 6/8/2020

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

CNA assigner: apache (f0158376-9dc2-43b6-827c-5f631a4d8d09) Requested by: n/a

Opam packages affected (1)

thrift

Products affected (1)

Product Vendor Version
Apache Thrift n/a V200R019C00SPC800

References (216)