Apache Thrift 0.25.0 fixes 61 CVEs in a jointly announced advisory
Notice from the oss-sec feed: Apache Thrift 0.25.0, released on 30 September 2026, fixes 61 vulnerabilities affecting earlier versions. The project recommends upgrading to 0.25.0.
On 4 October 2026, Jens Geyer posted to the oss-sec feed a message consolidating 61 vulnerabilities (CVEs) in Apache Thrift. According to the source, Apache Thrift 0.25.0 was released on 30 September 2026 and fixes all of them. All affect versions earlier than 0.25.0, and the text recommends that users upgrade to that version. Each of the 61 entries was announced on 1 October 2026 on the Apache Thrift announce list and on the user or developer list; the message replaces those 61 separate posts. The available text is a machine translation and does not detail each CVE individually in this record.
Thrift is an Apache project focused on serialization and communication between services. Anyone using it in integrations should check the installed version in their dependencies and plan the upgrade. Rota Nacional does not fix third-party libraries and does not replace that check. To consult the original, use the address given in the oss-sec record and the official Apache announcement, and compare versions and CVE identifiers with those published by the project.