CVE-2026-55971
Apache Thrift vulnerability analysis and mitigation

Overview

CVE-2026-55971 is a heap-based buffer overflow vulnerability in Apache Thrift C++ bindings, specifically identified as a ZLIB heap buffer overflow (write) in the THeaderTransport::untransform() function. It affects all versions of Apache Thrift prior to 0.24.0 and was publicly disclosed on July 24, 2026, with NVD analysis completed on July 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Apache Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and is rooted in improper bounds checking during ZLIB decompression within the THeaderTransport::untransform() function of the Apache Thrift C++ bindings. An unauthenticated remote attacker can send crafted network input to a Thrift service that triggers a heap buffer write overflow, potentially corrupting memory and enabling arbitrary code execution. No authentication, user interaction, or special privileges are required, and the attack complexity is low, making it highly automatable (Apache Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the process running the vulnerable Thrift application, resulting in full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability can also be leveraged to cause denial of service through process crashes. Given that Apache Thrift is widely used as an RPC framework across many enterprise applications, exploitation could facilitate lateral movement within internal networks if Thrift services are reachable from untrusted segments (Apache Advisory, GitHub Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 1.04% (61st percentile), indicating a moderate near-term exploitation probability relative to other CVEs. However, NVD's SSVC assessment notes the vulnerability is automatable with total technical impact, elevating its risk profile (GitHub Advisory).

Mitigation and workarounds

Apache has released version 0.24.0 of Apache Thrift, which resolves this vulnerability; all users are strongly recommended to upgrade immediately (Apache Advisory). Red Hat has issued security errata (RHSA-2026:49716 and RHSA-2026:52829) and openSUSE has published a security announcement for affected distributions. As an interim workaround where patching is not immediately possible, implement network segmentation to restrict access to Thrift services from untrusted networks and monitor for anomalous traffic targeting Thrift endpoints.

Community reactions

The vulnerability was announced on the Apache security mailing list and cross-posted to the oss-security list on July 24, 2026, generating early community awareness. Debian has submitted a packaging update (thrift 0.24.0-1) to address the issue, and multiple downstream vendors including Red Hat and openSUSE have issued advisories. Detection support has been added by Nessus (plugin 330406) and Qualys (IDs 6053406, 919427, 6053400), reflecting prompt response from the security tooling community (Apache Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Apache Thrift vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55971CRITICAL9.3
  • Apache Thrift logoApache Thrift
  • cpe:2.3:a:apache:thrift
NoYesJul 27, 2026
CVE-2026-58662HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58389HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58023MEDIUM6.9
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-66053MEDIUM5.9
  • Apache Thrift logoApache Thrift
  • python-thrift
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management