TL;DR
The Apache Thrift project has fixed 61 Apache Thrift vulnerabilities in version 0.25.0, published on October 2, 2026. Two flaws are rated critical at CVSS 9.2, 49 are high and 10 are medium. Most bugs let a remote peer crash or exhaust a Thrift service, while a few can corrupt memory.
- Total: 61 CVEs
- Severity: 2 Critical · 49 High · 10 Medium
- Actively exploited: None confirmed
- Highest severity: 9.2 (Critical · CVSSv4) — CVE-2026-83632
- Action: Apply the latest security updates now
See a Apache CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-83632 | 9.2 | C++ THttpTransport grows its line buffer without bound | 0.25.0 | Not exploited |
| CVE-2026-91135 | 9.2 | C++ `THeaderTransport::transform()` heap buffer overflow (write direction) | 0.25.0 | Not exploited |
| CVE-2026-61373 | 8.7 | Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation | 0.25.0 | Not exploited |
| CVE-2026-63772 | 8.7 | Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count | 0.25.0 | Not exploited |
| CVE-2026-66081 | 8.7 | c_glib read_message_begin leaves output parameters unset for non-versioned messages | 0.25.0 | Not exploited |
| CVE-2026-66837 | 8.7 | PHP accelerator sizes a stack buffer from a wire-controlled string length | 0.25.0 | Not exploited |
| CVE-2026-66858 | 8.7 | skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) | 0.25.0 | Not exploited |
| CVE-2026-66859 | 8.7 | c_glib multiplexed processor crashes on a message it cannot route | 0.25.0 | Not exploited |
Why It Matters
Thrift is an RPC framework that lets services written in different languages talk to each other. This batch touches at least 15 of its language bindings, including C++, Java, Go, Python, PHP, Node.js, Ruby and Erlang. As a result, almost every Thrift deployment needs the update.
So far, no exploitation in the wild or public proof-of-concept has been confirmed. Notably, the credits list many researchers. They include Sylwester Lachiewicz, Ada Logics and ZeroVuln Labs. Fourteen of the CVEs also credit AI agents from Anthropic’s Claude research team.
How the Attacks Work
Critical Heap Overflows
CVE-2026-91135 hits the C++ THeaderTransport. When an app turns on ZLIB compression, the transport copies the compressed frame without checking its size. Data that does not compress “grows under compression, so the copy writes past the end of the heap buffer,” the advisory states.
CVE-2026-83632, the other critical bug, combines unlimited resource allocation, an integer overflow and a heap-based buffer overflow. Both critical flaws need no authentication, though their CVSS vectors rate attack complexity as high.
Denial-of-Service Bugs
The bulk of the Apache Thrift vulnerabilities cause denial of service. Many bindings allocate memory without limits, recurse without bounds or loop forever on crafted input. For example, CVE-2026-66858 affects several bindings at once. Their skip routine ignored the recursion limit, so “a message that nests unknown fields deeply enough can exhaust the stack.”
Other bugs target specific servers. CVE-2026-61373 lets attackers exhaust memory on the Java TSaslNonblockingServer. Meanwhile, CVE-2026-63772 does the same to Go services, and several data amplification bugs abuse compressed data.
TLS and Other Flaws
Three medium bugs weaken certificate checks. CVE-2026-85088 lets the C++ and D libraries accept a certificate through its Common Name, even when its subjectAltName entries do not match. However, the advisory notes this is “principally a concern for deployments using a private or enterprise public-key infrastructure.” Other fixes address prototype pollution in the JavaScript bindings and memory leaks in C++.
Affected Versions
All 61 flaws affect Apache Thrift releases before 0.25.0. Some bugs reach back many years. For instance, CVE-2026-85088 affects the C++ library from 0.7.0 and the D library from 0.9.0.
Patch and Mitigation Steps
Upgrade every Thrift library and generated service to Apache Thrift 0.25.0. Rebuild applications that bundle Thrift, since many ship it as a dependency. Until then, keep Thrift endpoints off untrusted networks and set message size limits where the binding supports them.
Release details appear in the Apache Thrift security announcement on the project mailing list. Given the scale of these Apache Thrift vulnerabilities, teams should check every service that speaks the Thrift protocol.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!