CVE-2026-66859: Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift cglib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift c_glib bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using the Apache Thrift c_glib bindings with versions before 0.25.0 are affected. The issue is specifically associated with the c_glib multiplexed processor.
What must an attacker be able to do to trigger the issue?
The processor must receive a message that it cannot route. The provided information does not specify any additional authentication or access requirements.
What is the impact of a successful trigger?
A message the multiplexed processor cannot route can cause it to crash due to a NULL pointer dereference or use of an uninitialized variable.
What remediation is available?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.