Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Published Jul 27, 2026
8.7
HIGHCVSS 4.0
EPSS 1.03%
Description
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected products
-
- Version 0StatusaffectedConstraints<0.24.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Thrift | unaffected |
|
No data.
Red Hat Hardened Images
thrift-main-0.24.0-0.1.hum1
Fixed · RHSA-2026:49837
Confidential Compute Attestation
openshift-sandboxed-containers/osc-podvm-payload-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
thrift
Affected
Red Hat OpenShift Container Platform 4
conmon-rs
Not affected
Red Hat OpenShift Container Platform 4
kata-containers
Not affected
Red Hat OpenShift Update Service
openshift-update-service/openshift-update-service-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | thrift-main-0.24.0-0.1.hum1 | Fixed | RHSA-2026:49837 |
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | conmon-rs | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | kata-containers | Not affected | n/a |
| Red Hat OpenShift Update Service | openshift-update-service/openshift-update-service-rhel8 | Affected | n/a |
thrift
PyPI
Introduced 0 Fixed 0.24.0github.com/apache/thrift
Go
Introduced 0 Fixed 0.24.0apache/thrift
Packagist
Introduced 0 Fixed 0.24.0org.apache.thrift:libthrift
Maven
Introduced 0 Fixed 0.24.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| PyPI | thrift | 0 | 0.24.0 |
| Go | github.com/apache/thrift | 0 | 0.24.0 |
| Packagist | apache/thrift | 0 | 0.24.0 |
| Maven | org.apache.thrift:libthrift | 0 | 0.24.0 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.03% (0.01030) | 62.41th | v5 (v2026.06.15) |
| Jul 28, 2026 | 1.07% (0.01074) | 61.53th | v5 (v2026.06.15) |
References (8)
- http://www.openwall.com/lists/oss-security/2026/07/24/33 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-43871 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507441 Issue Tracking
- https://github.com/advisories/GHSA-8wv5-x4w7-5gww Advisory
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9 vendor-advisoryRelease Notes
- https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-43871
- https://www.cve.org/CVERecord?id=CVE-2026-43871
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/24/33 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-43871 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2507441 | Issue Tracking | |
| https://github.com/advisories/GHSA-8wv5-x4w7-5gww | Advisory | |
| https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9 | vendor-advisoryRelease Notes | |
| https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-43871 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-43871 |
Change history (0)
No recorded changes yet.