CVE-2026-96287: Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Perl bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift deployments using the Perl bindings are affected if they use a version before 0.25.0. The issue specifically involves FramedTransport reads and TLS socket writes.
What is the practical impact of this issue?
The affected operations re-slice the remaining buffer on every call, resulting in quadratic algorithmic complexity. Processing sufficiently large or fragmented data can therefore consume disproportionate resources.
What should teams do to remediate the issue?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue. The provided data does not identify an alternative mitigation for environments that cannot yet upgrade.