Uncontrolled Recursion Vulnerability in Apache Thrift Go Bindings
CVE-2026-83663
8.7HIGH
What is CVE-2026-83663?
An uncontrolled recursion vulnerability exists in the Go bindings of Apache Thrift that can result in a process termination. This issue arises when a buffered frame with zero payload is encountered. The Read function is recursively called without appropriate bounding conditions, leading to a stack overflow and fatal error. This vulnerability affects all versions of Apache Thrift prior to 0.25.0, and users are strongly advised to upgrade to the latest version to mitigate potential risks.
Affected Version(s)
Apache Thrift 0 < 0.25.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ho1aAs <xxy010605@gmail.com> for TFramedTransport
Apache Thrift Developers for THeaderTransport