Heap-based Buffer Overflow in Apache Thrift C++ Bindings
CVE-2026-55971

9.3CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 July 2026

What is CVE-2026-55971?

A heap-based buffer overflow vulnerability exists in the C++ bindings of Apache Thrift, which can potentially allow an attacker to execute arbitrary code by exploiting unvalidated input. This security flaw affects versions of Apache Thrift prior to 0.24.0. Users are advised to upgrade to version 0.24.0 or later to ensure protection against this vulnerability and enhance overall system security.

Affected Version(s)

Apache Thrift 0 < 0.24.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ghaith Abdulreda
.