CVE-2020-13949: Apache Hive

High severity, CVSS 7.5. EPSS: 6.8% chance of exploitation in the next 30 days.

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

Affected products

  • Apache Hive: before 4.0.0 (fixed in 4.0.0)
  • Apache Thrift: from 0.9.3, up to and including 0.13.0
  • Oracle Communications Cloud Native Core Network Slice Selection Function: version 1.2.1 only
  • Oracle Communications Cloud Native Core Policy: version 1.14.0 only

Published 2021-02-12. Last modified 2026-06-17.