Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN785 _____________________________________________________________________ DATE : 28/07/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Apache Thrift versions prior to 0.24.0. ===================================================================== https://lists.apache.org/thread/xn6mofhp9jonsvolc9d8psf26js6fpqc https://lists.apache.org/thread/f1y7jfh31q114gc5bk3j61cfw1tdg175 https://lists.apache.org/thread/mgm96z5n0dmf4nq1r4d3pty6pyg7o0vr https://lists.apache.org/thread/hdfxvtb21pb1fl5xyvp150fj1qyx5n06 https://lists.apache.org/thread/424yds6kpbszmnq7x2bxcxx8s3yylz6m https://lists.apache.org/thread/jpqfbd590p16qp0tb1p87ys9rbcb0y0w https://lists.apache.org/thread/ql8sxhlqc1723381l4v0tb0n05ob2rn9 https://lists.apache.org/thread/oyj3r0rplld63w6hgx1fz2f6df7bk984 https://lists.apache.org/thread/tjd14yykggwqb9nl6sc3lb14ytdjwqhw https://lists.apache.org/thread/gf9wdw55rx99rtjft4w5dfkhr84385d3 https://lists.apache.org/thread/405sv8ovq9360pgj1ogx2wwkj2cw3jh0 _____________________________________________________________________ CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport Severity: important Affected versions: - Apache Thrift (thrift) before 0.24.0 Description: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-41608 _____________________________________________________________________ CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 - Apache Thrift (github.com/apache/thrift) before 0.24.0 - Apache Thrift (apache/thrift) before 0.24.0 - Apache Thrift (org.apache.thrift:libthrift) before 0.24.0 Description: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: Yu Bao - yubao@paypal.com, who works for paypal.com (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-43871 _____________________________________________________________________ CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service Severity: Affected versions: - Apache Thrift (org.apache.thrift:libthrift) 0.19.0 before 0.24.0 Description: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: IcySun & Yashon (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-45112 _____________________________________________________________________ CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification Severity: Affected versions: - Apache Thrift (glibc language bindings) before 0.24.0 Description: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48144 _____________________________________________________________________ CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 Description: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48145 _____________________________________________________________________ CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 - Apache Thrift (github.com/apache/thrift) before 0.24.0 - Apache Thrift (c_glib) before 0.24.0 - Apache Thrift (org.apache.thrift:libthrift) before 0.24.0 - Apache Thrift (thrift) before 0.24.0 - Apache Thrift (D language) before 0.24.0 Description: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-48586 _____________________________________________________________________ CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb Severity: Affected versions: - Apache Thrift (ruby bindings) before 0.24.0 Description: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: LTSHFWJT <17...@qq.com> (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-49158 _____________________________________________________________________ CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 Description: Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: Song Jihoon (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55968 _____________________________________________________________________ CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 - Apache Thrift (c_glib language bindings) before 0.24.0 Description: Integer Overflow or Wraparound vulnerability in Apache Thrift C++ and c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: Ghaith Abdulreda (finder) Javid Khan (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55969 _____________________________________________________________________ Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 Description: Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: Ghaith Abdulreda (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55970 _____________________________________________________________________ CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() Severity: Affected versions: - Apache Thrift (thrift) before 0.24.0 Description: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Credit: Ghaith Abdulreda (finder) References: https://thrift.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-55971 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================