CVE-2020-13949General(apache / communications_cloud_native_core_network_slice_selection_function)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • communications_cloud_native_core_network_slice_selection_function
  • communications_cloud_native_core_policy
  • hive
  • thrift

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
communications_cloud_native_core_network_slice_selection_functioncommunications_cloud_native_core_policyhivethrift

2 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-05: 105-05
Signal classification1 categories
General
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • Open Source Security mailing list@oss_security
    General

    Apache Thrift CVE-2026-43868: Rust implementation vulnerable to CVE-2020-13949 https://www.openwall.com/lists/oss-security/2026/05/05/2 CVE-2026-43869: TSSLTransportFactory.⁠java hostname verification https://www.openwall.com/lists/oss-security/2026/05/05/3 CVE-2026-43870: Node.js web_server.js multi-vulnerability https://www.openwall.com/lists/oss-security/2026/05/05/4

    Post summary

    The passage simply lists three Apache Thrift CVEs with brief references and links to discussion threads, without providing detailed vulnerability data, proofs of exploitation, or remediation steps.

    02052471
    4.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehive---
Appapachethrift---
Apporaclecommunications_cloud_native_core_network_slice_selection_function1.2.1--
Apporaclecommunications_cloud_native_core_policy1.14.0--

Explore more