CVE-2026-55969
published 2026-07-27CVE-2026-55969: Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.65%
48.4th percentile
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | — | — |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| cryostat | cryostat-storage-rhel9 | — | — |
| kata-containers | kata-containers | — | — |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| openshift4 | cnf-tests-rhel8 | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhai | base-image-cpu-rhel9 | — | — |
| rhai | base-image-cuda-12.9-rhel9 | — | — |
| rhai | base-image-cuda-13.0-rhel9 | — | — |
| rhai | base-image-gaudi-rhel9 | — | — |
| rhai | base-image-neuron-rhel9 | — | — |
| rhai | base-image-rocm-6.4-rhel9 | — | — |
| rhai | base-image-rocm-7.0-rhel9 | — | — |
| rhai | base-image-rocm-7.1-rhel9 | — | — |
| rhai | base-image-spyre-rhel9 | — | — |
| rhai | base-image-tpu-rhel9 | — | — |
| rhaii | model-opt-cuda-rhel9 | — | — |
| rhaii | vllm-cpu-rhel9 | — | — |
| rhaii | vllm-cuda-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-55969 [HIGH] CWE-190 Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x checkReadBytesAvailable integer overflow
vuldb·2026-07-26
CVE-2026-55969 [LOW] Apache Thrift up to 0.23.x checkReadBytesAvailable integer overflow
A vulnerability, which was classified as problematic, was found in Apache Thrift up to 0.23.x. This affects the function TProtocol::checkReadBytesAvailable. Such manipulation leads to integer overflow.
This vulnerability is documented as CVE-2026-55969. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
Red Hat
thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-55969 [HIGH] CWE-190 thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound
thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound
A flaw was found in Apache Thrift's C++, c_glib, Go, netstd, Delphi, and Haxe bindings. This integer overflow or wraparound vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted input. The flaw can lead to the affected service becoming unavailable.
Statement: This vulnerability in Apache Thrift bindings, rated as Important, allows a remote attacker to trigger a denial of service. The integer overflow or wraparound flaw can lead to affected services becoming unavailable, impacting the reliability of systems utilizing vulnerable Thrift components across Red Hat products such as OpenShift Container Platform and Red Hat Ceph Storage.
Mitigati
No detection rules found.
No public exploits indexed.
2026-07-27
Published