{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/apache-thrift-prior-to-0.24.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-48586"},{"cvss":7.5,"id":"CVE-2026-49158"},{"cvss":7.5,"id":"CVE-2026-55969"},{"cvss":9.1,"id":"CVE-2026-58023"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Apache Thrift (Prior to 0.24.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","apache","library"],"_cs_type":"threat","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eThe Canadian Centre for Cyber Security (CCCS) has issued an advisory regarding multiple critical vulnerabilities affecting Apache Thrift, a framework for scalable cross-language services development. These vulnerabilities, identified as CVE-2026-48586, CVE-2026-49158, CVE-2026-55969, and CVE-2026-58023, impact all versions of Apache Thrift prior to 0.24.0. The issues include decompression size limits and bomb vulnerabilities in TZlibTransport and Ruby THeaderTransport, an integer overflow within TProtocol::checkReadBytesAvailable(), and a heap out-of-bounds read in the c_glib transport. While specific exploitation details are not provided, such vulnerabilities typically allow attackers to cause denial of service, corrupt memory, or potentially achieve arbitrary code execution. Organizations utilizing Apache Thrift are urged to update their installations to version 0.24.0 or later to mitigate these risks.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003eThe provided advisory describes vulnerabilities within the Apache Thrift library but does not detail a specific attack chain or observed exploitation in the wild. Exploitation would likely involve an attacker sending specially crafted input to an application utilizing the vulnerable Apache Thrift library, triggering one of the described flaws. For example, a malicious client could send compressed data designed to trigger a decompression bomb, leading to resource exhaustion, or a malformed request that causes an integer overflow or heap out-of-bounds read, which might lead to a crash, memory corruption, or even arbitrary code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to significant impact depending on the specific flaw and its context within an application. Decompression bombs (CVE-2026-48586, CVE-2026-49158) can cause denial of service by exhausting system resources (CPU, memory), making affected applications unavailable. Integer overflow (CVE-2026-55969) and heap out-of-bounds read (CVE-2026-58023) vulnerabilities can lead to application crashes, memory corruption, or in severe cases, remote code execution. This could allow an attacker to gain unauthorized control over the affected system, exfiltrate sensitive data, or further compromise the network. The broad use of Apache Thrift across various services means many applications could be at risk if not updated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview the Apache security advisories for CVE-2026-48586, CVE-2026-49158, CVE-2026-55969, and CVE-2026-58023 immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade all instances of Apache Thrift to version 0.24.0 or later to address the identified vulnerabilities.\u003c/li\u003e\n\u003cli\u003eConsult the provided reference links for detailed patching instructions and further information.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T14:35:38Z","date_published":"2026-07-28T14:35:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-apache-thrift-vulnerabilities/","summary":"Multiple vulnerabilities, including decompression bombs (CVE-2026-48586, CVE-2026-49158), an integer overflow (CVE-2026-55969), and a heap out-of-bounds read (CVE-2026-58023), affect Apache Thrift prior to version 0.24.0, potentially leading to denial of service, memory corruption, or arbitrary code execution, and require immediate patching.","title":"Multiple Vulnerabilities Identified in Apache Thrift","url":"https://feed.craftedsignal.io/briefs/2026-07-apache-thrift-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Apache Thrift (Prior to 0.24.0)","version":"https://jsonfeed.org/version/1.1"}