CVE-2026-66331: Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
Published Oct 2, 2026
·Updated
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
1 affected component
Apache Thrift<0.25.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Oct 2, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness