CVE-2026-82459: Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the Apache Thrift C++ THeaderTransport on 32-bit processes are affected if they run a version earlier than 0.25.0. The issue is reachable by an unauthenticated remote peer.
What does an attacker need to exploit it?
An attacker only needs network access sufficient to act as a remote peer to the affected THeaderTransport endpoint. No authentication is required according to the available information.
What is the remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.