CVE-2026-86537: Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service
Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the Apache Thrift D language bindings in versions earlier than 0.25.0 are affected. The issue concerns the D library's HTTP server handling.
What does an attacker need to do to exploit it?
An unauthenticated remote attacker can send a truncated HTTP request to the affected server. Successful exploitation can stop the server and cause denial of service.
Is there a configuration workaround if an upgrade cannot happen immediately?
No configuration workaround is provided in the available information. The stated remediation is to upgrade Apache Thrift to version 0.25.0.