Stack-based Buffer Overflow Vulnerability in Apache Thrift C++ THeaderProtocol
CVE-2026-93925

8.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-93925?

A stack-based buffer overflow vulnerability exists in the Apache Thrift C++ THeaderProtocol. This vulnerability arises due to an incorrect bitwise shift of an integer, potentially allowing an attacker to exploit the weakness. It has been reported to affect all versions prior to 0.25.0. To mitigate any risk associated with this flaw, users are strongly advised to upgrade to version 0.25.0, which resolves the issue and enhances overall security.

Affected Version(s)

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

glit3h from ZeroVuln Labs
.