<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Apache Thrift (Prior to 0.24.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/apache-thrift-prior-to-0.24.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 28 Jul 2026 14:35:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/apache-thrift-prior-to-0.24.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Vulnerabilities Identified in Apache Thrift</title><link>https://feed.craftedsignal.io/briefs/2026-07-apache-thrift-vulnerabilities/</link><pubDate>Tue, 28 Jul 2026 14:35:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-apache-thrift-vulnerabilities/</guid><description>Multiple vulnerabilities, including decompression bombs (CVE-2026-48586, CVE-2026-49158), an integer overflow (CVE-2026-55969), and a heap out-of-bounds read (CVE-2026-58023), affect Apache Thrift prior to version 0.24.0, potentially leading to denial of service, memory corruption, or arbitrary code execution, and require immediate patching.</description><content:encoded><![CDATA[<p>The Canadian Centre for Cyber Security (CCCS) has issued an advisory regarding multiple critical vulnerabilities affecting Apache Thrift, a framework for scalable cross-language services development. These vulnerabilities, identified as CVE-2026-48586, CVE-2026-49158, CVE-2026-55969, and CVE-2026-58023, impact all versions of Apache Thrift prior to 0.24.0. The issues include decompression size limits and bomb vulnerabilities in TZlibTransport and Ruby THeaderTransport, an integer overflow within TProtocol::checkReadBytesAvailable(), and a heap out-of-bounds read in the c_glib transport. While specific exploitation details are not provided, such vulnerabilities typically allow attackers to cause denial of service, corrupt memory, or potentially achieve arbitrary code execution. Organizations utilizing Apache Thrift are urged to update their installations to version 0.24.0 or later to mitigate these risks.</p>
<h2 id="attack-chain">Attack Chain</h2>
<p>The provided advisory describes vulnerabilities within the Apache Thrift library but does not detail a specific attack chain or observed exploitation in the wild. Exploitation would likely involve an attacker sending specially crafted input to an application utilizing the vulnerable Apache Thrift library, triggering one of the described flaws. For example, a malicious client could send compressed data designed to trigger a decompression bomb, leading to resource exhaustion, or a malformed request that causes an integer overflow or heap out-of-bounds read, which might lead to a crash, memory corruption, or even arbitrary code execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could lead to significant impact depending on the specific flaw and its context within an application. Decompression bombs (CVE-2026-48586, CVE-2026-49158) can cause denial of service by exhausting system resources (CPU, memory), making affected applications unavailable. Integer overflow (CVE-2026-55969) and heap out-of-bounds read (CVE-2026-58023) vulnerabilities can lead to application crashes, memory corruption, or in severe cases, remote code execution. This could allow an attacker to gain unauthorized control over the affected system, exfiltrate sensitive data, or further compromise the network. The broad use of Apache Thrift across various services means many applications could be at risk if not updated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Review the Apache security advisories for CVE-2026-48586, CVE-2026-49158, CVE-2026-55969, and CVE-2026-58023 immediately.</li>
<li>Upgrade all instances of Apache Thrift to version 0.24.0 or later to address the identified vulnerabilities.</li>
<li>Consult the provided reference links for detailed patching instructions and further information.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>apache</category><category>library</category></item></channel></rss>