This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat hummingbird |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:hummingbird:1 | |
| Vendors & Products |
Redhat
Redhat hummingbird |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 02 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Title | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-02T16:54:25.933Z
Reserved: 2026-07-27T22:27:11.611Z
Link: CVE-2026-66858
Updated: 2026-10-02T16:54:18.940Z
Status : Deferred
Published: 2026-10-02T13:17:53.453
Modified: 2026-10-02T17:17:07.357
Link: CVE-2026-66858
OpenCVE Enrichment
Updated: 2026-10-03T01:30:18Z