Heap-based buffer overflow in Apache Thrift - CVE-2026-55971
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in THeaderTransport::untransform() when processing ZLIB-compressed data. A remote attacker can send specially crafted compressed input to cause a denial of service or execute arbitrary code.