Apache Thrift 0.25.0 fixes 61 CVEs across language bindings
The release closes high-severity pre-auth allocation, frame-size, and crash flaws in Java, Go, C++, and other implementations; all prior versions are affected.
By nonceThe release closes high-severity pre-auth allocation, frame-size, and crash flaws in Java, Go, C++, and other implementations; all prior versions are affected.
By noncePath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitThe July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpit