CVE-2026-58023
Apache Thrift vulnerability analysis and mitigation

Overview

CVE-2026-58023 is an Out-of-bounds Read vulnerability (CWE-125) in the Apache Thrift c_glib (GLib) language bindings, specifically in the transport leftover-bytes processing path. It affects all versions of Apache Thrift before 0.24.0 and was disclosed by Apache on July 24, 2026, with NVD publication on July 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 6.9 (Medium) (Apache Advisory, GitHub Advisory).

Technical details

The root cause is an out-of-bounds read (CWE-125, CAPEC-540: Overread Buffers) in the c_glib transport layer of Apache Thrift, where insufficient bounds checking during leftover-bytes handling allows a read beyond the intended buffer boundary. An unauthenticated remote attacker can send a specially crafted network message to a service using the vulnerable c_glib bindings, triggering the out-of-bounds read without requiring any privileges or user interaction. The attack vector is network-accessible, with low complexity and no prerequisites beyond reaching the exposed Thrift service endpoint (Apache Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an unauthenticated network attacker to disclose sensitive memory contents (information disclosure) and cause a denial of service by crashing the affected service. The confidentiality impact is limited to the vulnerable system's memory, with no integrity impact; however, the availability impact can be significant if the Thrift-based service is critical to operations. Only applications using the c_glib language bindings of Apache Thrift are affected — other language bindings are not impacted (GitHub Advisory, Red Hat Bugzilla).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Apache Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is automatable. The EPSS score is approximately 1.08% (62nd percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Apache Thrift to version 0.24.0 or later, which contains the fix for this vulnerability (Apache Advisory). If immediate patching is not feasible, organizations should isolate systems running vulnerable versions of Apache Thrift c_glib bindings from untrusted network sources and restrict network access to only trusted clients. Detection is available via Nessus plugin 330392 and Qualys detection ID 919459 (GitHub Advisory).

Community reactions

The Canadian Centre for Cyber Security (CCCS) issued security advisory AV26-749 referencing this vulnerability, and Red Hat opened a tracking bug (BZ#2507440) with medium severity. OpenSUSE also issued a security announcement for affected packages. Community coverage has been limited to standard vulnerability aggregator sites, with no notable researcher commentary or significant social media discussion observed (CCCS Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Apache Thrift vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55971CRITICAL9.3
  • Apache Thrift logoApache Thrift
  • cpe:2.3:a:apache:thrift
NoYesJul 27, 2026
CVE-2026-58662HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58389HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58023MEDIUM6.9
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-66053MEDIUM5.9
  • Apache Thrift logoApache Thrift
  • python-thrift
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management