Apache Thrift 0.25.0 was released on 30 September 2026:
https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
It fixes the 61 vulnerabilities listed below. All of them affect Apache
Thrift before 0.25.0, and users are recommended to upgrade to 0.25.0.
Each was announced on 1 October 2026 on [email protected] and on the
Apache Thrift user or dev list; this message replaces the 61 separate
postings to this list.
Each entry gives the CVSS 4.0 score, the ASF rating, the title, the
affected language bindings and a link to the full announcement (severity
vector, weakness, description and credit). The CVE records are at
https://www.cve.org/CVERecord?id=<CVE id>.
CVE-2026-61373 8.7 important Java TSaslNonblockingServer pre-auth
unbounded SASL frame allocation
Bindings: Java
https://lists.apache.org/thread/shy1rrm2g383wlbdb2p7w19c868ntdjp
CVE-2026-61374 7.1 important Java TSaslTransport post-auth data-frame
missing size limit
Bindings: Java
https://lists.apache.org/thread/35831rngzrqky1gvc32t06psgq1b8441
CVE-2026-63772 8.7 important Unauthenticated single-packet crash of Go
Thrift servers via the THeader transform
count
Bindings: Go
https://lists.apache.org/thread/6kpzdw29gsfxptv4b65y9s6f42tdyo8k
CVE-2026-66054 6.9 moderate C++ THeaderTransport does not enforce
configured maxFrameSize
Bindings: C++
https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33
CVE-2026-66055 8.2 important TJSONProtocol accepts a single JSON
string/number exceeding the configured size
limit (multi-language)
Bindings: C++, Java, Go, netstd, Python,
Delphi
https://lists.apache.org/thread/nxlmlhgsh7fwr4mo1fkhtkw3v266qhcx
CVE-2026-66081 8.7 important c_glib read_message_begin leaves output
parameters unset for non-versioned messages
Bindings: c_glib
https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57
CVE-2026-66331 6.9 moderate Buffered transport reads are not accounted
against MaxMessageSize
Bindings: Delphi
https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143
CVE-2026-66837 8.7 important PHP accelerator sizes a stack buffer from a
wire-controlled string length
Bindings: PHP
https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1
CVE-2026-66858 8.7 important skip() does not apply the recursion limit
(Python accelerator, PHP, Perl, Lua,
Smalltalk, OCaml)
Bindings: Python, PHP, Perl, Lua, Smalltalk,
OCaml
https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5
CVE-2026-66859 8.7 important c_glib multiplexed processor crashes on a
message it cannot route
Bindings: c_glib
https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o
CVE-2026-82458 8.7 important Container element count not bounded by the
bytes available
Bindings: Go, Rust, netstd, OCaml, Erlang,
JavaME, C++, Java, Kotlin, D
https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7
CVE-2026-82459 8.2 important Integer underflow in C++ THeaderTransport
allows an unauthenticated remote peer to
terminate a 32-bit process
Bindings: C++
https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2
CVE-2026-83632 9.2 critical C++ THttpTransport grows its line buffer
without bound
Bindings: C++
https://lists.apache.org/thread/zjv6hjmhl4tb4l4l1dk4bmc2whxh0lb4
CVE-2026-83663 8.7 important TFramedTransport and THeaderTransport
re-enter Read once per frame that carries no
payload (Go)
Bindings: Go
https://lists.apache.org/thread/yjz317wq7h86q9k8ws6ton0ojgl8hjct
CVE-2026-83745 8.7 important WebSocket frame decoders allocate the payload
buffer from the declared length, not the
bytes received (Node.js, D)
Bindings: Node.js, D
https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc
CVE-2026-85086 6.9 moderate Perl TLS client disables certificate
verification by default
Bindings: Perl
https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy
CVE-2026-85087 6.9 moderate Python ≥3.12 host-name check silently becomes
a no-op
Bindings: Python
https://lists.apache.org/thread/l2rgp3dqhpy2w347forzdt9g7o2d6k0d
CVE-2026-85088 6.9 moderate The C++ and D clients fall back to the
certificate Common Name when subjectAltName
entries are present but do not match
Bindings: C++, D
https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371
CVE-2026-85476 8.2 important c_glib `read_all` spins when the underlying
read returns 0
Bindings: c_glib
https://lists.apache.org/thread/1zdvscq7p3hf3z30s26h4tm9dvljm1jj
CVE-2026-85483 6.3 moderate c_glib TZlibTransport reports a full read
after a premature stream end
Bindings: c_glib
https://lists.apache.org/thread/ro1y0ckzfzcc45yk9qkt1p6t4g2jvrfy
CVE-2026-85493 8.7 important TProtocolUtil.skip follows peer-chosen
nesting to any depth the stack allows (Dart,
Java ME)
Bindings: Dart, JavaME
https://lists.apache.org/thread/oqr0h2k1cg9hho3oh8trmovmxc04fl5m
CVE-2026-85494 8.7 important Framed transport and binary protocol size a
read buffer from a peer-declared length with
no effective maximum (multi-language)
Bindings: Python, Ruby, Erlang, Lua, Dart,
JavaME, D, Perl, PHP
https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr
CVE-2026-86535 8.7 important A JSON member name can stall the Node
server's event loop indefinitely
Bindings: Node.js
https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g
CVE-2026-86536 6.3 moderate A map key from the wire can replace a decoded
object's prototype in generated JavaScript
Bindings: Node.js, JavaScript, TypeScript
https://lists.apache.org/thread/xckvfky30kdnk8vqnhy0wndthvc9nymp
CVE-2026-86537 8.7 important A truncated HTTP request stops the D
library's server, allowing an
unauthenticated
remote attacker to deny service
Bindings: D
https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m
CVE-2026-87117 8.7 important PHP `thrift_protocol` accelerator
dereferences a missing container-element
spec
Bindings: PHP
https://lists.apache.org/thread/y05tvpv19ow44j16gtbcy9ht7lb0qjpy
CVE-2026-90440 8.2 important An exception escaping a libevent callback
stops the D library's non-blocking server,
allowing an unauthenticated remote attacker
to deny service
Bindings: D
https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg
CVE-2026-91135 9.2 critical C++ `THeaderTransport::transform()` heap
buffer overflow (write direction)
Bindings: C++
https://lists.apache.org/thread/rbpwlhlxnv2qgyk8cfscp2d2fd3p0ojb
CVE-2026-91137 8.7 important PHP `thrift_protocol` accelerator: zero-byte
container elements
Bindings: PHP
https://lists.apache.org/thread/bf12g1b11r4x9x3wsy4mgwfgd0t779h7
CVE-2026-92834 6.3 moderate C++ WebSocket server transport does not read
a full request length
Bindings: C++
https://lists.apache.org/thread/bjor9ttx7hk23gzcx60ohz0f20xzvgv0
CVE-2026-93925 8.7 important C++ `THeaderTransport::writeVarint32()` stack
buffer overflow on a negative protocol id
Bindings: C++
https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9
CVE-2026-93926 8.7 important C++ `THeaderTransport::untransform()` leaks
the zlib stream on the error path
Bindings: C++
https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb
CVE-2026-94633 8.7 important Dart `TBinaryProtocol.readMessageBegin`
allocates from the pre-versioned name length
Bindings: Dart
https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k
CVE-2026-94634 8.2 important Python `TJSONProtocol` has a string length
limit that is off by default
Bindings: Python
https://lists.apache.org/thread/dgy8ox9t4bh1xhf74ovf29ht87x7dno4
CVE-2026-94635 8.7 important Lua `TBinaryProtocol:readMessageBegin`
bypasses `checkStringSize` on the
pre-versioned name
Bindings: Lua
https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3
CVE-2026-94636 8.2 important Python `TZlibTransport` stops enforcing its
decompressed-size limit once the limit is
exactly used up
Bindings: Python
https://lists.apache.org/thread/1rpq0d0g6yzjjzl1z27lwmvhzkn6rbrs
CVE-2026-94637 8.2 important Go `THeaderTransport` does not bound the
inflated size of a ZLIB frame
Bindings: Go
https://lists.apache.org/thread/6hxll1jcnod9gfr225tz7my08lpj3jmt
CVE-2026-94638 6.3 moderate PHP `thrift_protocol` C extension ignores the
configured `maxStringSize`
Bindings: PHP
https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj
CVE-2026-94639 8.2 important Java `TSaslNonblockingServer`: residual of
CVE-2026-61373 (thread-death black hole + no
cross-connection budget)
Bindings: Java
https://lists.apache.org/thread/5okpz47dv8hy0s3r6tmrplg3y7jzhhyw
CVE-2026-94642 8.7 important PHP `TSimpleServer` exits the whole process
on any non-transport exception
Bindings: PHP
https://lists.apache.org/thread/5tjwbbyympbj16lblocv9b12s32sg113
CVE-2026-94644 8.2 important PHP `TJSONProtocol` string/number readers
have no size bound
Bindings: PHP
https://lists.apache.org/thread/8y04vvxw7ozxxh3c44vhoy7jsd6bonzq
CVE-2026-94645 8.2 important Node.js `TJSONProtocol` uses a peer-declared
container size as an unbounded loop bound
Bindings: Node.js
https://lists.apache.org/thread/p96mokqfy16mnqfyon46mf6g8nr9ghb6
CVE-2026-94646 8.7 important Node.js `server.js` ends the process on any
per-connection error (+ two triggers)
Bindings: Node.js
https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8
CVE-2026-94648 8.2 important dart `TJsonProtocol`/`TJSONProtocol` has no
string size bound
Bindings: Dart
https://lists.apache.org/thread/f9w4q6ttlc3k9404x4do25gdhqodtjnn
CVE-2026-94650 8.2 important c_glib generated struct readers have no
recursion-depth guard (native stack
exhaustion)
Bindings: c_glib
https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j
CVE-2026-94651 8.2 important Java `TSaslNonblockingServer`
`Computation.run` orphans a connection on a
pre-auth parse error
Bindings: Java
https://lists.apache.org/thread/rflzpdvtk8yhpzg99wkf5yf277nn7267
CVE-2026-94652 6.3 moderate C++ `TEvhttpServer` leaks its
`RequestContext` when the processor throws
before calling back
Bindings: C++
https://lists.apache.org/thread/nodwz7gjvogkkh3w1jwbsslk1c7t0727
CVE-2026-94653 8.2 important PHP framed/memory/HTTP transports re-slice
the buffer on every read (quadratic)
Bindings: PHP
https://lists.apache.org/thread/8zbv1y4wzr3nn5mzmdph7b0n6tm0lc4m
CVE-2026-94654 8.2 important Python `TNonblockingServer` busy-loops and
stops selecting all fds after an
8192-byte-boundary frame
Bindings: Python
https://lists.apache.org/thread/kx3xdttoypl8j4dcxmqbq9dwy1w0kr7j
CVE-2026-94655 8.2 important Lua `TJsonProtocol` string/number readers
have no size bound and are quadratic
Bindings: Lua
https://lists.apache.org/thread/wdjyf4y115ybgdzz5m3gspo97lcmz1dt
CVE-2026-94656 8.2 important rb `TJsonProtocol`/`TJSONProtocol` has no
string size bound
Bindings: Ruby
https://lists.apache.org/thread/lg97w2yvg3c6z06l8m5xs3j3v2m6mvj8
CVE-2026-94657 8.2 important javame `TJsonProtocol`/`TJSONProtocol` has no
string size bound
Bindings: JavaME
https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14
CVE-2026-94658 8.7 important Lua `TFramedTransport`/`THttpTransport`
re-slice the buffer on every read
(quadratic)
Bindings: Lua
https://lists.apache.org/thread/hv6b1nyk2p15gy5pmtprwo7z9m46mfcx
CVE-2026-96277 8.7 important Ruby `SimpleServer` ends `serve()` on any
non-Transport/Protocol exception
Bindings: Ruby
https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098
CVE-2026-96286 8.2 important Perl servers end `serve()` when serving one
connection fails
Bindings: Perl
https://lists.apache.org/thread/o5386v7ytbbjv9sx7dbszw46ypod5yd9
CVE-2026-96287 8.2 important Perl `FramedTransport` reads and TLS socket
writes re-slice the remaining buffer on
every
call (quadratic)
Bindings: Perl
https://lists.apache.org/thread/tcg16jr59z5nry066dw7ym60vl25dxt9
CVE-2026-96288 8.2 important Erlang generated struct reads have no
recursion-depth guard (unbounded memory)
Bindings: Erlang
https://lists.apache.org/thread/vxnk7cmdtoqjn97b8szlqym1mxx0xtzb
CVE-2026-96289 8.2 important php `--gen php:inlined` struct readers (and
`TProtocol::skipBinary`) have no
recursion-depth guard
Bindings: PHP
https://lists.apache.org/thread/kv1zkwlt82lkkv20g29txr5pjnvo0pf8
CVE-2026-96292 8.2 important Lua `THttpTransport:_parseHeaders` matches
each header line with a backtracking pattern
(quadratic)
Bindings: Lua
https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn
CVE-2026-96294 8.7 important nodejs web server: no `error` listener on an
upgraded WebSocket connection
Bindings: Node.js
https://lists.apache.org/thread/52gwhsy947hj9qhgn0dql726z1q927g4
CVE-2026-96990 8.2 important Erlang thrift_json_protocol reads a whole
message with no size bound
Bindings: Erlang
https://lists.apache.org/thread/hrgcqlms4ksrz4qkqdjwoxxggdty7dgh
Jens Geyer, for the Apache Thrift PMC
--
Drafted with AI assistance (Claude Opus 5.5); reviewed and sent by Jens
Geyer.