Description
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Improper Resource Handling leading to possible denial of service
Action: Patch Now
AI Analysis

Impact

The flaw in Apache Thrift’s c_glib TZlibTransport causes the RPC layer to perform a full read after a premature stream end or to return an incorrect status code, exposing the system to uninitialized resource usage. This can result in corrupted data being returned to callers, unexpected application behavior, or a logic‑based denial of service if the transport repeatedly encounters incomplete reads.

Affected Systems

Apache Thrift components built against versions earlier than 0.25.0, particularly the c_glib binding utilizing TZlibTransport, are vulnerable. All deployments that use these bindings without the patch are affected.

Risk and Exploitability

With a CVSS score of 6.3 the vulnerability is considered medium severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, reducing the probability of already known exploitation. The attack vector is not explicitly described in the advisory; however, the flaw is reachable via networked Thrift calls that exercise the TZlibTransport endpoint, suggesting a remote or, at minimum, a local attack could trigger the premature read and corrupt the transport state.

Generated by OpenCVE AI on October 2, 2026 at 13:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later.
  • Disable the c_glib TZlibTransport in configurations if it is not required for your deployment.
  • Review code paths that interact with Thrift transports to ensure resources are fully initialized before use.

Generated by OpenCVE AI on October 2, 2026 at 13:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end
Weaknesses CWE-393
CWE-908
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T16:12:58.415Z

Reserved: 2026-09-03T21:18:47.539Z

Link: CVE-2026-85483

cve-icon Vulnrichment

Updated: 2026-10-02T16:12:53.783Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:35.740

Modified: 2026-10-02T17:17:07.720

Link: CVE-2026-85483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:15:07Z

Weaknesses
  • CWE-393

    Return of Wrong Status Code

  • CWE-908

    Use of Uninitialized Resource