https://seclists.org/oss-sec/2026/q3/271: CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
Frequently Asked Questions
1
What is the severity of CVE-2026-55971?
CVE-2026-55971 is a high-severity heap buffer overflow vulnerability.
2
How do I fix CVE-2026-55971?
To fix CVE-2026-55971, upgrade Apache Thrift to version 0.24.0 or later.
3
Which versions of Apache Thrift are affected by CVE-2026-55971?
CVE-2026-55971 affects Apache Thrift versions before 0.24.0.
4
What is the impact of CVE-2026-55971 on systems?
The impact of CVE-2026-55971 can lead to heap-based buffer overflow, potentially allowing arbitrary code execution.
5
Who reported CVE-2026-55971?
CVE-2026-55971 was reported by researcher Ghaith Abdulred.