CVE-2026-55971
Apache Thrift C++ bindings contain a heap‑based buffer overflow that can be triggered remotely. The flaw exists in all releases before 0.24.0 and can allow an attacker to run arbitrary code. Upgrading to 0.24.0 or later removes the vulnerability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Thrift C++ bindings, versions prior to 0.24.0, used by developers building distributed systems.
Real-world impact
An attacker could exploit the overflow to execute arbitrary code on a system that uses the vulnerable Thrift library, potentially taking full control of the affected application.
Why this severity
The CVSS score of 9.3 reflects the high impact of the vulnerability: it requires no user interaction, can be triggered remotely, and allows an attacker to gain complete control over the affected system.
What to do about it
- 01Upgrade Apache Thrift to version 0.24.0 or later.
- 02Restart any services that use the Thrift library to ensure the new version is loaded.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.apache.org/thread/7v3jhgwfbmhx42424phy…release notes
- lists.apache.org/thread/xjs36m6kjxpmrmzwck63…vendor advisory
- openwall.com/lists/oss-security/2026/07/…mailing listthird party advisory