PT-2026-64878 · Apache · Apache Thrift

CVE-2026-43871

·

Published

2026-07-27

·

Updated

2026-09-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description An infinite loop issue exists in the Python, Go, PHP, and Java bindings of Apache Thrift. This occurs due to a loop with an unreachable exit condition within the TCompactProtocol varint byte-count limit.
Recommendations Upgrade to version 0.24.0.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93995
AZL-94163
AZL-94220
AZL-94235
AZL-94320
AZL-94329
BIT-THRIFT-2026-43871
CVE-2026-43871
ECHO-7F9D-9D60-D057
GHSA-8WV5-X4W7-5GWW
OPENSUSE-SU-2026:11432-1
PYSEC-2026-3926

Affected Products

Apache Thrift