CVE-2026-94633: Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length
Published Oct 2, 2026
·Updated
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
1 affected component
Apache Thrift<0.25.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Dart bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Oct 2, 2026
CVE Published
via MITRE·10:13 AM
Data Sourced
via MITRE·10:13 AM
DescriptionWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Apache Thrift Dart bindings before version 0.25.0 are affected. The provided information does not identify other language bindings as affected.
2
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.