
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58023 is an Out-of-bounds Read vulnerability (CWE-125) in the Apache Thrift c_glib (GLib) language bindings, specifically in the transport leftover-bytes processing path. It affects all versions of Apache Thrift before 0.24.0 and was disclosed by Apache on July 24, 2026, with NVD publication on July 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 6.9 (Medium) (Apache Advisory, GitHub Advisory).
The root cause is an out-of-bounds read (CWE-125, CAPEC-540: Overread Buffers) in the c_glib transport layer of Apache Thrift, where insufficient bounds checking during leftover-bytes handling allows a read beyond the intended buffer boundary. An unauthenticated remote attacker can send a specially crafted network message to a service using the vulnerable c_glib bindings, triggering the out-of-bounds read without requiring any privileges or user interaction. The attack vector is network-accessible, with low complexity and no prerequisites beyond reaching the exposed Thrift service endpoint (Apache Advisory, Red Hat Bugzilla).
Successful exploitation allows an unauthenticated network attacker to disclose sensitive memory contents (information disclosure) and cause a denial of service by crashing the affected service. The confidentiality impact is limited to the vulnerable system's memory, with no integrity impact; however, the availability impact can be significant if the Thrift-based service is critical to operations. Only applications using the c_glib language bindings of Apache Thrift are affected — other language bindings are not impacted (GitHub Advisory, Red Hat Bugzilla).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Apache Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is automatable. The EPSS score is approximately 1.08% (62nd percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory).
The primary remediation is to upgrade Apache Thrift to version 0.24.0 or later, which contains the fix for this vulnerability (Apache Advisory). If immediate patching is not feasible, organizations should isolate systems running vulnerable versions of Apache Thrift c_glib bindings from untrusted network sources and restrict network access to only trusted clients. Detection is available via Nessus plugin 330392 and Qualys detection ID 919459 (GitHub Advisory).
The Canadian Centre for Cyber Security (CCCS) issued security advisory AV26-749 referencing this vulnerability, and Red Hat opened a tracking bug (BZ#2507440) with medium severity. OpenSUSE also issued a security announcement for affected packages. Community coverage has been limited to standard vulnerability aggregator sites, with no notable researcher commentary or significant social media discussion observed (CCCS Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."