CVE-2026-83663: Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)

Published Oct 2, 2026
·
Updated

Uncontrolled Recursion vulnerability in Apache Thrift go bindings.

Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call Read again instead of looping. A peer produces such a frame for 4 bytes in TFramedTransport (a declared size of zero) or 18 bytes in THeaderTransport (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a fatal error, which recover() cannot catch, so the whole process dies.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected Software

1 affected component
Apache Thrift<0.25.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Thrift Go bindings to a version that resolves this vulnerability.

    Fixed in 0.25.0

Event History

Oct 2, 2026
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using the Apache Thrift Go bindings before version 0.25.0 are affected when they use TFramedTransport or THeaderTransport and can receive frames from a peer.

2

What must an attacker send to trigger the process crash?

The peer must repeatedly send payload-free frames: zero-length declared frames for TFramedTransport, or THeaderTransport frames whose header block fills the frame. Each such frame causes another nested Read call until the Go stack limit terminates the process.

3

Can application-level panic recovery prevent the crash?

No. Reaching the Go stack limit produces a fatal error, and recover() cannot catch it, so the entire process dies.

4

What is the available remediation?

Upgrade Apache Thrift to version 0.25.0, which fixes the recursive read behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203