๐Ÿ” CVE Alert

CVE-2026-85494

UNKNOWN 0.0

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CWE CWE-130 CWE-248 CWE-407 CWE-789 CWE-1188
Vendor apache software foundation
Product apache thrift
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache thrift

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache thrift are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1 lists.apache.org: https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr

Credits

Ho1aAs <[email protected]> for py, rb, erl, lua, dart, javame, d bindings Perl/PHP bindings were found by the Apache Thrift project's own cross-language sweep The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift.