CVE-2026-55969: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Other sources
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, cglib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.4-12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.24.0-1 - Upgrade
Upgrade
apache/thriftto a version that resolves this vulnerability.Fixed in 0.24.0Patch CVE-2026-55969
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55969?
CVE-2026-55969 has been classified with a medium severity score due to the potential for exploitation leading to a denial of service.
How do I fix CVE-2026-55969?
To fix CVE-2026-55969, update your Apache Thrift installation to the latest available version that addresses this vulnerability.
What systems are affected by CVE-2026-55969?
CVE-2026-55969 affects multiple versions of Apache Thrift prior to the patch release that resolves the integer overflow issue.
What type of vulnerability is CVE-2026-55969?
CVE-2026-55969 is an integer overflow vulnerability in the TProtocol::checkadBytesAvailable() method.
What are the potential impacts of CVE-2026-55969?
The potential impacts of CVE-2026-55969 include denial of service attacks, which could disrupt normal functioning of applications using affected versions of Apache Thrift.