CVE-2021-24028

CRITICAL

Facebook Thrift <2021.02.22.00 - Code Injection

Title source: llm
STIX 2.1

Description

An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.

Scores

CVSS v3 9.8
EPSS 0.0167
EPSS Percentile 82.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-763
Status published
Products (1)
facebook/thrift < 2021.02.22.00
Published Apr 14, 2021
Tracked Since Feb 18, 2026