https://seclists.org/oss-sec/2026/q3/271: CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
CVE-2026-55971 is a high-severity heap buffer overflow vulnerability.
To fix CVE-2026-55971, upgrade Apache Thrift to version 0.24.0 or later.
CVE-2026-55971 affects Apache Thrift versions before 0.24.0.
The impact of CVE-2026-55971 can lead to heap-based buffer overflow, potentially allowing arbitrary code execution.
CVE-2026-55971 was reported by researcher Ghaith Abdulred.