|
|
Message-ID: <01bb4946-c936-4a44-8b69-f44c9e793e10@apache.org> Date: Sun, 4 Oct 2026 08:51:50 +0200 From: Jens Geyer <jensg@...che.org> To: oss-security@...ts.openwall.com Cc: private@...ift.apache.org Subject: Apache Thrift 0.25.0: 61 CVEs fixed (combined announcement) Apache Thrift 0.25.0 was released on 30 September 2026: https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1 It fixes the 61 vulnerabilities listed below. All of them affect Apache Thrift before 0.25.0, and users are recommended to upgrade to 0.25.0. Each was announced on 1 October 2026 on announce@...che.org and on the Apache Thrift user or dev list; this message replaces the 61 separate postings to this list. Each entry gives the CVSS 4.0 score, the ASF rating, the title, the affected language bindings and a link to the full announcement (severity vector, weakness, description and credit). The CVE records are at https://www.cve.org/CVERecord?id=<CVE id>. CVE-2026-61373 8.7 important Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation Bindings: Java https://lists.apache.org/thread/shy1rrm2g383wlbdb2p7w19c868ntdjp CVE-2026-61374 7.1 important Java TSaslTransport post-auth data-frame missing size limit Bindings: Java https://lists.apache.org/thread/35831rngzrqky1gvc32t06psgq1b8441 CVE-2026-63772 8.7 important Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count Bindings: Go https://lists.apache.org/thread/6kpzdw29gsfxptv4b65y9s6f42tdyo8k CVE-2026-66054 6.9 moderate C++ THeaderTransport does not enforce configured maxFrameSize Bindings: C++ https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33 CVE-2026-66055 8.2 important TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) Bindings: C++, Java, Go, netstd, Python, Delphi https://lists.apache.org/thread/nxlmlhgsh7fwr4mo1fkhtkw3v266qhcx CVE-2026-66081 8.7 important c_glib read_message_begin leaves output parameters unset for non-versioned messages Bindings: c_glib https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57 CVE-2026-66331 6.9 moderate Buffered transport reads are not accounted against MaxMessageSize Bindings: Delphi https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143 CVE-2026-66837 8.7 important PHP accelerator sizes a stack buffer from a wire-controlled string length Bindings: PHP https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1 CVE-2026-66858 8.7 important skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) Bindings: Python, PHP, Perl, Lua, Smalltalk, OCaml https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5 CVE-2026-66859 8.7 important c_glib multiplexed processor crashes on a message it cannot route Bindings: c_glib https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o CVE-2026-82458 8.7 important Container element count not bounded by the bytes available Bindings: Go, Rust, netstd, OCaml, Erlang, JavaME, C++, Java, Kotlin, D https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7 CVE-2026-82459 8.2 important Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process Bindings: C++ https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2 CVE-2026-83632 9.2 critical C++ THttpTransport grows its line buffer without bound Bindings: C++ https://lists.apache.org/thread/zjv6hjmhl4tb4l4l1dk4bmc2whxh0lb4 CVE-2026-83663 8.7 important TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go) Bindings: Go https://lists.apache.org/thread/yjz317wq7h86q9k8ws6ton0ojgl8hjct CVE-2026-83745 8.7 important WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D) Bindings: Node.js, D https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc CVE-2026-85086 6.9 moderate Perl TLS client disables certificate verification by default Bindings: Perl https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy CVE-2026-85087 6.9 moderate Python ≥3.12 host-name check silently becomes a no-op Bindings: Python https://lists.apache.org/thread/l2rgp3dqhpy2w347forzdt9g7o2d6k0d CVE-2026-85088 6.9 moderate The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match Bindings: C++, D https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371 CVE-2026-85476 8.2 important c_glib `read_all` spins when the underlying read returns 0 Bindings: c_glib https://lists.apache.org/thread/1zdvscq7p3hf3z30s26h4tm9dvljm1jj CVE-2026-85483 6.3 moderate c_glib TZlibTransport reports a full read after a premature stream end Bindings: c_glib https://lists.apache.org/thread/ro1y0ckzfzcc45yk9qkt1p6t4g2jvrfy CVE-2026-85493 8.7 important TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME) Bindings: Dart, JavaME https://lists.apache.org/thread/oqr0h2k1cg9hho3oh8trmovmxc04fl5m CVE-2026-85494 8.7 important Framed transport and binary protocol size a read buffer from a peer-declared length with no effective maximum (multi-language) Bindings: Python, Ruby, Erlang, Lua, Dart, JavaME, D, Perl, PHP https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr CVE-2026-86535 8.7 important A JSON member name can stall the Node server's event loop indefinitely Bindings: Node.js https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g CVE-2026-86536 6.3 moderate A map key from the wire can replace a decoded object's prototype in generated JavaScript Bindings: Node.js, JavaScript, TypeScript https://lists.apache.org/thread/xckvfky30kdnk8vqnhy0wndthvc9nymp CVE-2026-86537 8.7 important A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service Bindings: D https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m CVE-2026-87117 8.7 important PHP `thrift_protocol` accelerator dereferences a missing container-element spec Bindings: PHP https://lists.apache.org/thread/y05tvpv19ow44j16gtbcy9ht7lb0qjpy CVE-2026-90440 8.2 important An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service Bindings: D https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg CVE-2026-91135 9.2 critical C++ `THeaderTransport::transform()` heap buffer overflow (write direction) Bindings: C++ https://lists.apache.org/thread/rbpwlhlxnv2qgyk8cfscp2d2fd3p0ojb CVE-2026-91137 8.7 important PHP `thrift_protocol` accelerator: zero-byte container elements Bindings: PHP https://lists.apache.org/thread/bf12g1b11r4x9x3wsy4mgwfgd0t779h7 CVE-2026-92834 6.3 moderate C++ WebSocket server transport does not read a full request length Bindings: C++ https://lists.apache.org/thread/bjor9ttx7hk23gzcx60ohz0f20xzvgv0 CVE-2026-93925 8.7 important C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id Bindings: C++ https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9 CVE-2026-93926 8.7 important C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path Bindings: C++ https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb CVE-2026-94633 8.7 important Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length Bindings: Dart https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k CVE-2026-94634 8.2 important Python `TJSONProtocol` has a string length limit that is off by default Bindings: Python https://lists.apache.org/thread/dgy8ox9t4bh1xhf74ovf29ht87x7dno4 CVE-2026-94635 8.7 important Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name Bindings: Lua https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3 CVE-2026-94636 8.2 important Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up Bindings: Python https://lists.apache.org/thread/1rpq0d0g6yzjjzl1z27lwmvhzkn6rbrs CVE-2026-94637 8.2 important Go `THeaderTransport` does not bound the inflated size of a ZLIB frame Bindings: Go https://lists.apache.org/thread/6hxll1jcnod9gfr225tz7my08lpj3jmt CVE-2026-94638 6.3 moderate PHP `thrift_protocol` C extension ignores the configured `maxStringSize` Bindings: PHP https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj CVE-2026-94639 8.2 important Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget) Bindings: Java https://lists.apache.org/thread/5okpz47dv8hy0s3r6tmrplg3y7jzhhyw CVE-2026-94642 8.7 important PHP `TSimpleServer` exits the whole process on any non-transport exception Bindings: PHP https://lists.apache.org/thread/5tjwbbyympbj16lblocv9b12s32sg113 CVE-2026-94644 8.2 important PHP `TJSONProtocol` string/number readers have no size bound Bindings: PHP https://lists.apache.org/thread/8y04vvxw7ozxxh3c44vhoy7jsd6bonzq CVE-2026-94645 8.2 important Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound Bindings: Node.js https://lists.apache.org/thread/p96mokqfy16mnqfyon46mf6g8nr9ghb6 CVE-2026-94646 8.7 important Node.js `server.js` ends the process on any per-connection error (+ two triggers) Bindings: Node.js https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8 CVE-2026-94648 8.2 important dart `TJsonProtocol`/`TJSONProtocol` has no string size bound Bindings: Dart https://lists.apache.org/thread/f9w4q6ttlc3k9404x4do25gdhqodtjnn CVE-2026-94650 8.2 important c_glib generated struct readers have no recursion-depth guard (native stack exhaustion) Bindings: c_glib https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j CVE-2026-94651 8.2 important Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error Bindings: Java https://lists.apache.org/thread/rflzpdvtk8yhpzg99wkf5yf277nn7267 CVE-2026-94652 6.3 moderate C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back Bindings: C++ https://lists.apache.org/thread/nodwz7gjvogkkh3w1jwbsslk1c7t0727 CVE-2026-94653 8.2 important PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic) Bindings: PHP https://lists.apache.org/thread/8zbv1y4wzr3nn5mzmdph7b0n6tm0lc4m CVE-2026-94654 8.2 important Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame Bindings: Python https://lists.apache.org/thread/kx3xdttoypl8j4dcxmqbq9dwy1w0kr7j CVE-2026-94655 8.2 important Lua `TJsonProtocol` string/number readers have no size bound and are quadratic Bindings: Lua https://lists.apache.org/thread/wdjyf4y115ybgdzz5m3gspo97lcmz1dt CVE-2026-94656 8.2 important rb `TJsonProtocol`/`TJSONProtocol` has no string size bound Bindings: Ruby https://lists.apache.org/thread/lg97w2yvg3c6z06l8m5xs3j3v2m6mvj8 CVE-2026-94657 8.2 important javame `TJsonProtocol`/`TJSONProtocol` has no string size bound Bindings: JavaME https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14 CVE-2026-94658 8.7 important Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic) Bindings: Lua https://lists.apache.org/thread/hv6b1nyk2p15gy5pmtprwo7z9m46mfcx CVE-2026-96277 8.7 important Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception Bindings: Ruby https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098 CVE-2026-96286 8.2 important Perl servers end `serve()` when serving one connection fails Bindings: Perl https://lists.apache.org/thread/o5386v7ytbbjv9sx7dbszw46ypod5yd9 CVE-2026-96287 8.2 important Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic) Bindings: Perl https://lists.apache.org/thread/tcg16jr59z5nry066dw7ym60vl25dxt9 CVE-2026-96288 8.2 important Erlang generated struct reads have no recursion-depth guard (unbounded memory) Bindings: Erlang https://lists.apache.org/thread/vxnk7cmdtoqjn97b8szlqym1mxx0xtzb CVE-2026-96289 8.2 important php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard Bindings: PHP https://lists.apache.org/thread/kv1zkwlt82lkkv20g29txr5pjnvo0pf8 CVE-2026-96292 8.2 important Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic) Bindings: Lua https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn CVE-2026-96294 8.7 important nodejs web server: no `error` listener on an upgraded WebSocket connection Bindings: Node.js https://lists.apache.org/thread/52gwhsy947hj9qhgn0dql726z1q927g4 CVE-2026-96990 8.2 important Erlang thrift_json_protocol reads a whole message with no size bound Bindings: Erlang https://lists.apache.org/thread/hrgcqlms4ksrz4qkqdjwoxxggdty7dgh Jens Geyer, for the Apache Thrift PMC -- Drafted with AI assistance (Claude Opus 5.5); reviewed and sent by Jens Geyer.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.