CVE-2026-43871
published 2026-07-27CVE-2026-43871: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.61%
46.7th percentile
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | — | — |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
ghsa_unreviewed·2026-07-27
CVE-2026-43871 [HIGH] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x TCompactProtocol infinite loop
vuldb·2026-07-26
CVE-2026-43871 [LOW] Apache Thrift up to 0.23.x TCompactProtocol infinite loop
A vulnerability categorized as problematic has been discovered in Apache Thrift up to 0.23.x. Affected by this vulnerability is an unknown functionality of the component TCompactProtocol. The manipulation results in infinite loop.
This vulnerability was named CVE-2026-43871. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
Red Hat
thrift: Apache Thrift: Denial of Service via infinite loop
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-43871 [HIGH] CWE-835 thrift: Apache Thrift: Denial of Service via infinite loop
thrift: Apache Thrift: Denial of Service via infinite loop
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can trigger a continuous loop, leading to a denial of service (DoS) for applications using the affected bindings.
Package: openshift-sandboxed-containers/osc-podvm-payload-rhel9 (Confidential Compute Attestation) - Affected
Package: thrift (Red Hat Enterpri
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [epel-all]
bugzilla·2026-07-28·CVSS 7.5
CVE-2026-43871 [HIGH] CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [epel-all]
CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [fedora-all]
bugzilla·2026-07-28·CVSS 7.5
CVE-2026-43871 [HIGH] CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [fedora-all]
CVE-2026-43871 thrift: Apache Thrift: Denial of Service via infinite loop [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-43871 kata-containers: Apache Thrift: Denial of Service via infinite loop [fedora-all]
bugzilla·2026-07-28·CVSS 7.5
CVE-2026-43871 [HIGH] CVE-2026-43871 kata-containers: Apache Thrift: Denial of Service via infinite loop [fedora-all]
CVE-2026-43871 kata-containers: Apache Thrift: Denial of Service via infinite loop [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published