CVE-2026-66858: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thriftprotocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use Apache Thrift before 0.25.0 with the Python C++ accelerator, the PHP library or thrift_protocol extension, or the Perl, Lua, Smalltalk, or OCaml libraries. Pure-Python Thrift protocols are not affected.
What does an attacker need to send to trigger the issue?
The attacker needs to supply a message containing unknown fields nested deeply enough to exhaust the stack. The affected skip routine does not enforce the binding's recursion limit while processing those fields.
What should teams do if they use an affected binding?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue. The provided information does not specify an alternative configuration workaround for affected versions.
How can I determine whether a service may be vulnerable?
Identify the Thrift binding used by the service and its version. A service may be vulnerable if it uses one of the listed affected bindings on a version earlier than 0.25.0; services using only pure-Python protocols are not affected.