CVE-2026-82458: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available
Published Oct 2, 2026
·Updated
Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
1 affected component
Apache Thrift<0.25.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Oct 2, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Apache Thrift language bindings are affected?
The affected bindings are Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin, and D. The issue affects Apache Thrift versions before 0.25.0.
2
What is the remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.