CVE-2026-85483: Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift cglib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift deployments using the c_glib bindings before version 0.25.0 are affected. The issue is specifically associated with TZlibTransport.
Does exploitation require authentication or user interaction?
The supplied CVSS vector indicates network reachability, low attack complexity, no privileges required, and no user interaction. It also indicates that an attack prerequisite is present (AT:P).
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.