Buffer Over-read Vulnerability in Apache Thrift by Apache
CVE-2026-55970

6.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 July 2026

What is CVE-2026-55970?

A buffer over-read vulnerability exists in Apache Thrift's C++ bindings, which can lead to the exposure of sensitive information or unintended behavior in applications. This vulnerability affects versions prior to 0.24.0. Users are strongly advised to upgrade to version 0.24.0 to mitigate potential risks.

Affected Version(s)

Apache Thrift 0 < 0.24.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ghaith Abdulreda
.