Apache · Apache Thrift · CVE-2026-55969
**Name of the Vulnerable Software and Affected Versions**
Apache Thrift versions prior to 0.24.0
**Description**
An integer overflow or wraparound issue exists in the C++, c glib, Go, netstd, Delphi, and Haxe bindings. The flaw is located in the `checkReadBytesAvailable()` function of the `TProtocol` class.
**Recommendations**
Upgrade to version 0.24.0.