Description
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap‑based buffer overflow arises when the C++ THttpTransport component in Apache Thrift expands its line buffer without constraining the size of incoming data. The absence of size limits coupled with integer overflow and wrap‑around vulnerabilities allows an attacker to supply excessive input that corrupts memory. If an attacker succeeds, they could crash the Thrift service or potentially execute arbitrary code, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

Apache Software Foundation’s Apache Thrift is affected in all releases prior to version 0.25.0. Any deployment running a version older than 0.25.0 that utilizes the C++ THttpTransport transport layer is susceptible to the described flaw.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.2, denoting critical severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but the high CVSS score suggests that exploitation would enable an attacker to gain remote execution privileges. The likely attack vector is remote, as the thickness of data is controlled via HTTP requests to the Thrift service. Exploitation requires network access to the Thrift service and relies on the ability to send unbounded or malformed input that triggers the integer overflow and subsequent buffer overflow.

Generated by OpenCVE AI on October 2, 2026 at 13:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Thrift 0.25.0 or later, which contains the fix for the buffer overflow.
  • If an upgrade is infeasible, limit the size of incoming data at the network or application layer to prevent excessive buffer growth, for example by configuring appropriate request size limits on the HTTP endpoint that fronts the Thrift service.
  • Implement rate limiting or firewall rules to restrict the volume of requests to the Thrift service, mitigating the risk of resource exhaustion or denial of service attacks arising from the unbounded buffer growth.

Generated by OpenCVE AI on October 2, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: C++ THttpTransport grows its line buffer without bound
Weaknesses CWE-122
CWE-190
CWE-770
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T12:22:23.617Z

Reserved: 2026-08-31T21:54:56.725Z

Link: CVE-2026-83632

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T13:17:58.647

Modified: 2026-10-02T13:17:58.647

Link: CVE-2026-83632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound

  • CWE-770

    Allocation of Resources Without Limits or Throttling