← All credits
Sylwester Lachiewicz
15 vulnerability records and advisories credit this contributor.
CVE-2026-94652
Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back
CVE-2026-94648
Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-94645
Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound
CVE-2026-94644
Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound
CVE-2026-94642
Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception
CVE-2026-94639
Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
CVE-2026-94638
Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize`
CVE-2026-94637
Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame
CVE-2026-94657
Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-94656
Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound