Package
vector
Component
thrift
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable thrift crate is a transitive dependency pinned to ^0.17 by parquet. The fix (thrift 0.23.0) is a semver-incompatible major bump that no released parquet version yet supports, and the package is already built from the latest upstream release. Pending an upstream parquet/arrow-rs update that drops or migrates the thrift dependency.
Status