Inefficient Algorithmic Complexity in Apache Thrift - CVE-2026-55968
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity and allocation of resources without limits or throttling in Node.js server receive transports when processing input. A remote attacker can send specially crafted input to cause a denial of service.
Affected software
Anolis OS
python3-thrift
thrift
thrift-devel
thrift-glib
thrift-qt
perl-thrift
How to mitigate CVE-2026-55968
python3-thrift - update to 0.24.0-1
thrift - update to 0.24.0-1
thrift-devel - update to 0.24.0-1
thrift-glib - update to 0.24.0-1
thrift-qt - update to 0.24.0-1
perl-thrift - update to 0.24.0-1