PT-2026-64878 · Apache · Apache Thrift

CVE-2026-43871

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description An infinite loop issue exists in the Python, Go, PHP, and Java bindings of Apache Thrift. This occurs due to a loop with an unreachable exit condition within the TCompactProtocol varint byte-count limit.
Recommendations Upgrade to version 0.24.0.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43871

Affected Products

Apache Thrift