CVE-2026-66837: Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length
Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift PHP bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift installations using the PHP bindings are affected if they run a version before 0.25.0. The issue is in the PHP accelerator's handling of a string length supplied on the wire.
What must an attacker control to trigger the issue?
An attacker needs to provide Thrift wire data containing a controlled string length. That length can cause integer overflow or wraparound and lead the PHP accelerator to size a stack buffer incorrectly.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.