CVE-2026-66858: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)

Published Oct 2, 2026
·
Updated

The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thriftprotocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected Software

1 affected component
Apache Thrift<0.25.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Thrift to a version that resolves this vulnerability.

    Fixed in 0.25.0

Event History

Oct 2, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments use Apache Thrift before 0.25.0 with the Python C++ accelerator, the PHP library or thrift_protocol extension, or the Perl, Lua, Smalltalk, or OCaml libraries. Pure-Python Thrift protocols are not affected.

2

What does an attacker need to send to trigger the issue?

The attacker needs to supply a message containing unknown fields nested deeply enough to exhaust the stack. The affected skip routine does not enforce the binding's recursion limit while processing those fields.

3

What should teams do if they use an affected binding?

Upgrade Apache Thrift to version 0.25.0, which fixes the issue. The provided information does not specify an alternative configuration workaround for affected versions.

4

How can I determine whether a service may be vulnerable?

Identify the Thrift binding used by the service and its version. A service may be vulnerable if it uses one of the listed affected bindings on a version earlier than 0.25.0; services using only pure-Python protocols are not affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203