CVE-2026-63772: Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Go bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift Go bindings versions before 0.25.0 are affected. The provided information does not identify any configuration prerequisite.
What access does an attacker need?
The issue is described as unauthenticated and exploitable with a single packet against Go Thrift servers. This indicates an attacker does not need to authenticate before sending the triggering traffic.
What is the impact of successful exploitation?
Successful exploitation can crash a Go Thrift server through unbounded resource allocation related to the THeader transform count.
What should teams do to remediate the issue?
Upgrade Apache Thrift Go bindings to version 0.25.0, which fixes the issue.