CVE-2026-58662
published 2026-07-27CVE-2026-58662: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.64%
48.0th percentile
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-58662 [HIGH] CWE-125 Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x Header Length readString memory corruption
vuldb·2026-07-26
CVE-2026-58662 [CRITICAL] Apache Thrift up to 0.23.x Header Length readString memory corruption
A vulnerability was found in Apache Thrift up to 0.23.x. It has been rated as critical. This affects the function THeaderTransport::readString of the component Header Length Handler. This manipulation causes memory corruption.
This vulnerability is handled as CVE-2026-58662. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-27
Published