Description
Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.



When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

Heap-based buffer overflow occurs in the Apache Thrift C++ THeaderTransport::transform() function when the ZLIB transform is enabled. The function copies compressed frames into a write buffer without verifying that the compressed data fits, causing an out‑of‑bounds write. The overflow can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or cause a crash. This flaw is a classic example of CWE‑122.

Affected Systems

Applications built with Apache Thrift versions earlier than 0.25.0 are affected. The vulnerability arises when the ZLIB transform is used for frames sent by a remote peer. Any deployment that accepts untrusted Thrift traffic and enables ZLIB processing on outgoing frames is at risk.

Risk and Exploitability

With a CVSS score of 9.2 the risk is high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the overflow by sending large, poorly compressing frames over a network connection that the Thrift service accepts. The attack vector is remote and does not require authentication, as any client can supply frames that carry the malicious payload.

Generated by OpenCVE AI on October 2, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Thrift 0.25.0 or later to apply the official fix.
  • Disable the ZLIB transform for frames wherever possible to avoid the overflow until a patch is deployed.
  • Add bounds checking or enforce strict limits on the size of frames before processing to mitigate the risk of overflow in older versions.

Generated by OpenCVE AI on October 2, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction)
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:28:50.745Z

Reserved: 2026-09-14T19:41:58.259Z

Link: CVE-2026-91135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:37.277

Modified: 2026-10-02T11:17:37.277

Link: CVE-2026-91135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:30:19Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow