
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55971 is a heap-based buffer overflow vulnerability in Apache Thrift C++ bindings, specifically identified as a ZLIB heap buffer overflow (write) in the THeaderTransport::untransform() function. It affects all versions of Apache Thrift prior to 0.24.0 and was publicly disclosed on July 24, 2026, with NVD analysis completed on July 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Apache Advisory, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and is rooted in improper bounds checking during ZLIB decompression within the THeaderTransport::untransform() function of the Apache Thrift C++ bindings. An unauthenticated remote attacker can send crafted network input to a Thrift service that triggers a heap buffer write overflow, potentially corrupting memory and enabling arbitrary code execution. No authentication, user interaction, or special privileges are required, and the attack complexity is low, making it highly automatable (Apache Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the process running the vulnerable Thrift application, resulting in full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability can also be leveraged to cause denial of service through process crashes. Given that Apache Thrift is widely used as an RPC framework across many enterprise applications, exploitation could facilitate lateral movement within internal networks if Thrift services are reachable from untrusted segments (Apache Advisory, GitHub Advisory).
As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 1.04% (61st percentile), indicating a moderate near-term exploitation probability relative to other CVEs. However, NVD's SSVC assessment notes the vulnerability is automatable with total technical impact, elevating its risk profile (GitHub Advisory).
Apache has released version 0.24.0 of Apache Thrift, which resolves this vulnerability; all users are strongly recommended to upgrade immediately (Apache Advisory). Red Hat has issued security errata (RHSA-2026:49716 and RHSA-2026:52829) and openSUSE has published a security announcement for affected distributions. As an interim workaround where patching is not immediately possible, implement network segmentation to restrict access to Thrift services from untrusted networks and monitor for anomalous traffic targeting Thrift endpoints.
The vulnerability was announced on the Apache security mailing list and cross-posted to the oss-security list on July 24, 2026, generating early community awareness. Debian has submitted a packaging update (thrift 0.24.0-1) to address the issue, and multiple downstream vendors including Red Hat and openSUSE have issued advisories. Detection support has been added by Nessus (plugin 330406) and Qualys (IDs 6053406, 919427, 6053400), reflecting prompt response from the security tooling community (Apache Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."