CVE-2026-91137: Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements
Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift PHP bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift PHP bindings are affected when using versions before 0.25.0. The issue is specifically associated with the PHP thrift_protocol accelerator.
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.
What is the likely security impact?
The vulnerability can affect availability. It involves improper quantity validation, unbounded resource allocation, and excessive iteration; the supplied CVSS vector indicates no confidentiality or integrity impact.
What should teams do to remediate this issue?
Upgrade Apache Thrift to version 0.25.0. The provided advisory information identifies 0.25.0 as the version that fixes the issue.