{"id":"GO-2021-0101","summary":"Panic due to out-of-bounds read in github.com/apache/thrift","details":"Due to an improper bounds check, parsing maliciously crafted messages can cause panics. If this package is used to parse untrusted input, this may be used as a vector for a denial of service attack.","aliases":["CVE-2019-0210","GHSA-jq7p-26h5-w78r"],"modified":"2026-03-17T04:09:05.684643Z","published":"2021-07-28T18:08:05Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2021-0101"},"references":[{"type":"FIX","url":"https://github.com/apache/thrift/commit/264a3f318ed3e9e51573f67f963c8509786bcec2"}],"affected":[{"package":{"name":"github.com/apache/thrift","ecosystem":"Go","purl":"pkg:golang/github.com/apache/thrift"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20151001171628-53dd39833a08"},{"fixed":"0.13.0"}]}],"ecosystem_specific":{"imports":[{"symbols":["Skip","SkipDefaultDepth","TBinaryProtocol.Skip","TCompactProtocol.Skip","TJSONProtocol.ParseElemListBegin","TJSONProtocol.ReadBool","TJSONProtocol.ReadByte","TJSONProtocol.ReadDouble","TJSONProtocol.ReadFieldBegin","TJSONProtocol.ReadFieldEnd","TJSONProtocol.ReadI16","TJSONProtocol.ReadI32","TJSONProtocol.ReadI64","TJSONProtocol.ReadListBegin","TJSONProtocol.ReadListEnd","TJSONProtocol.ReadMapBegin","TJSONProtocol.ReadMapEnd","TJSONProtocol.ReadMessageBegin","TJSONProtocol.ReadMessageEnd","TJSONProtocol.ReadSetBegin","TJSONProtocol.ReadSetEnd","TJSONProtocol.ReadStructBegin","TJSONProtocol.ReadStructEnd","TJSONProtocol.Skip","TSimpleJSONProtocol.ParseElemListBegin","TSimpleJSONProtocol.ParseF64","TSimpleJSONProtocol.ParseI64","TSimpleJSONProtocol.ParseListBegin","TSimpleJSONProtocol.ParseListEnd","TSimpleJSONProtocol.ParseObjectEnd","TSimpleJSONProtocol.ParseObjectStart","TSimpleJSONProtocol.ReadByte","TSimpleJSONProtocol.ReadDouble","TSimpleJSONProtocol.ReadI16","TSimpleJSONProtocol.ReadI32","TSimpleJSONProtocol.ReadI64","TSimpleJSONProtocol.ReadListBegin","TSimpleJSONProtocol.ReadListEnd","TSimpleJSONProtocol.ReadMapBegin","TSimpleJSONProtocol.ReadMapEnd","TSimpleJSONProtocol.ReadMessageBegin","TSimpleJSONProtocol.ReadMessageEnd","TSimpleJSONProtocol.ReadSetBegin","TSimpleJSONProtocol.ReadSetEnd","TSimpleJSONProtocol.ReadStructBegin","TSimpleJSONProtocol.ReadStructEnd","TSimpleJSONProtocol.Skip","TSimpleJSONProtocol.safePeekContains","TStandardClient.Call","TStandardClient.Recv","tApplicationException.Read"],"path":"github.com/apache/thrift/lib/go/thrift"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0101.json"}}],"schema_version":"1.7.5"}