CVE-2026-55970
published 2026-07-27CVE-2026-55970: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
0.48%
39.5th percentile
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | — | — |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| rhai | base-image-cpu-rhel9 | — | — |
| rhai | base-image-cuda-12.9-rhel9 | — | — |
| rhai | base-image-cuda-13.0-rhel9 | — | — |
| rhai | base-image-gaudi-rhel9 | — | — |
| rhai | base-image-neuron-rhel9 | — | — |
| rhai | base-image-rocm-6.4-rhel9 | — | — |
| rhai | base-image-rocm-7.0-rhel9 | — | — |
| rhai | base-image-rocm-7.1-rhel9 | — | — |
| rhai | base-image-spyre-rhel9 | — | — |
| rhai | base-image-tpu-rhel9 | — | — |
| rhaii | model-opt-cuda-rhel9 | — | — |
| rhaii | vllm-cpu-rhel9 | — | — |
| rhaii | vllm-cuda-rhel9 | — | — |
| rhaii | vllm-gaudi-rhel9 | — | — |
| rhaii | vllm-neuron-rhel9 | — | — |
| rhaii | vllm-rocm-rhel9 | — | — |
| rhaii | vllm-spyre-rhel9 | — | — |
| rhaii | vllm-tpu-rhel9 | — | — |
| rhaiis | model-opt-cuda-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
vendor_redhat·2026-07-27·CVSS 6.5
CVE-2026-55970 [MEDIUM] CWE-125 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
A flaw was found in Apache Thrift C++ bindings. This buffer over-read vulnerability allows a remote attacker to read beyond the intended memory boundaries. This could lead to the disclosure of sensitive information or cause the application to become unavailable.
Statement: This Moderate impact vulnerability in Apache Thrift C++ bindings could lead to information disclosure due to a buffer over-read. Red Hat products utilizing affected versions of Apache Thrift, such as Red Hat Enterprise Linux AI, OpenShift Container Platform, and Red Hat OpenShift AI, may be susceptible if processing untrusted data with Thrift client applications.
Package: openshift-sandboxed-containers/osc-podvm-payload-rh
GHSA
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-55970 [MEDIUM] CWE-126 Buffer Over-read vulnerability in Apache Thrift C++ bindings.
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x readHeaderFormat out-of-bounds
vuldb·2026-07-26
CVE-2026-55970 [LOW] Apache Thrift up to 0.23.x readHeaderFormat out-of-bounds
A vulnerability has been found in Apache Thrift up to 0.23.x and classified as problematic. This impacts the function THeaderTransport::readHeaderFormat. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-55970. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [epel-all]
bugzilla·2026-08-12·CVSS 6.5
CVE-2026-55970 [MEDIUM] CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [epel-all]
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-55970 kata-containers: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
bugzilla·2026-08-12·CVSS 6.5
CVE-2026-55970 [MEDIUM] CVE-2026-55970 kata-containers: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
CVE-2026-55970 kata-containers: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
bugzilla·2026-08-12·CVSS 6.5
CVE-2026-55970 [MEDIUM] CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
bugzilla·2026-07-27·CVSS 6.5
CVE-2026-55970 [MEDIUM] CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
CVE-2026-55970 thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published