CVE-2026-87117: Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec
NULL pointer dereference vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift PHP bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize applications using the Apache Thrift PHP bindings and the PHP thrift_protocol accelerator on versions earlier than 0.25.0.
How can I tell whether an installation is affected?
Check the installed Apache Thrift version used by the PHP bindings. Versions before 0.25.0 are affected; version 0.25.0 contains the fix.
What should be done if the environment is affected?
Upgrade Apache Thrift to version 0.25.0. The available information does not identify an alternative workaround or configuration-based mitigation.