PT-2026-64891 · Apache · Apache Thrift

CVE-2026-58389

·

Published

2026-07-27

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description An allocation of resources without limits or throttling issue exists in the Apache Thrift Rust bindings. Specifically, the Rust binary protocol non-strict path lacks a string size limit, which could lead to excessive resource consumption.
Recommendations Update to version 0.24.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-THRIFT-2026-58389
CVE-2026-58389
OPENSUSE-SU-2026:11432-1

Affected Products

Apache Thrift