In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
{
"cpes": [
"cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*"
],
"severity": "High"
}