node.js bindings for the Apache Thrift RPC system
77%
Total Score
72
86
65
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-185433 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. thrift is vulnerable to Denial of Service (DoS) in versions 0.7.0 - 0.23.0. | 0.7.0 - 0.23.0 | Medium |
CVE-2026-43870 thrift is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.22.0. | 0.0.0 - 0.22.0 | High |
AIKIDO-2026-10700 thrift is vulnerable to Uncontrolled Recursion in versions 0.2.1 - 0.22.0. | 0.2.1 - 0.22.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^8.21.0 | — | — |
uuid Version ^14.0.0 | — | — |
node-int64 Version ^0.4.0 | — | — |
isomorphic-ws Version ^4.0.1 | — | — |
browser-or-node Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant