CVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Published:
7/27/2026
Last updated:
7/27/2026
Reserved:
6/17/2026
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
CNA assigner:
apache (f0158376-9dc2-43b6-827c-5f631a4d8d09)
Requested by:
n/a
Opam packages affected (1)
thrift
Credits (3)
-
1
Ghaith Abdulreda
-
1
Javid Khan
-
1
Apache Thrift Developers