CVE-2026-85494: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which language bindings are affected?
The affected Apache Thrift bindings are Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP, and D. The issue affects versions before 0.25.0.
What does an attacker need to do to trigger the issue?
An attacker needs to act as, or otherwise control, a peer that can supply a declared length to the framed transport or binary protocol. The affected bindings read buffers based on that peer-declared length without a limit.
Are deployments affected by default?
The vulnerability description identifies initialization of a resource with an insecure default, and states that peer-declared lengths are read without a limit. Any affected binding using the framed transport or binary protocol with untrusted peers should be treated as exposed until upgraded.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0. This version fixes the issue.