Heap-Based Buffer Overflow in Apache Thrift THeaderTransport
CVE-2026-91135

9.2CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-91135?

A heap-based buffer overflow vulnerability exists in Apache Thrift C++ THeaderTransport, which occurs when the ZLIB transform is enabled for sent frames. The method THeaderTransport::transform() copies the compressed frame into a write buffer without properly checking its size. This flaw can lead to out-of-bounds writing as certain uncompressed data, supplied by a remote peer, may increase in size upon compression, thereby exceeding the buffer’s limits. This vulnerability affects versions prior to 0.25.0, and users are advised to upgrade to version 0.25.0 to mitigate this risk.

Affected Version(s)

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

glit3h from ZeroVuln Labs
.