CVE-2026-94637: Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame
Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Go bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift Go bindings are affected if they use a version before 0.25.0. The issue is specifically in Go THeaderTransport handling of ZLIB frames.
What must an attacker provide to trigger the issue?
An attacker needs to provide a highly compressed ZLIB frame. The vulnerability results from the transport not bounding the frame's inflated size, enabling data amplification.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.