CVE-2016-5397: Apache Thrift
High severity, CVSS 8.8. EPSS: 6.9% chance of exploitation in the next 30 days.
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Affected products
- Apache Thrift: up to and including 0.9.3
Published 2018-02-12. Last modified 2026-06-17.