PT-2026-64885 · Apache · Apache Thrift

·

CVE-2026-55969

·

Published

2026-07-27

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description An integer overflow or wraparound issue exists in the C++, c glib, Go, netstd, Delphi, and Haxe bindings. The flaw is located in the checkReadBytesAvailable() function of the TProtocol class.
Recommendations Upgrade to version 0.24.0.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93992
AZL-94160
AZL-94217
AZL-94232
AZL-94317
AZL-94332
BIT-THRIFT-2026-55969
CVE-2026-55969
ECHO-61D4-277D-88D0
OPENSUSE-SU-2026:11432-1
RHSA-2026:46974
RHSA-2026:46987
RHSA-2026:46989

Affected Products

Apache Thrift