CVE-2019-0210: Apache Thrift

High severity, CVSS 7.5. EPSS: 6.4% chance of exploitation in the next 30 days.

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Affected products

  • Apache Thrift: from 0.9.3, up to and including 0.12.0
  • Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
  • Red Hat JBoss Enterprise Application Platform: version 7.2.0 only

Published 2019-10-29. Last modified 2026-06-17.