Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-83632: Apache Thrift may overflow memory and crash

CVE-2026-83632 · published 8 days ago
Summary

The Apache Thrift library used in Debian and Ubuntu can mishandle data, leading to unlimited resource use and a memory overflow that could let attackers crash or take control of the system. Upgrade the Thrift package to version 0.25.0 to apply the fix.

What to do
  • Update apache software foundation apache thrift to version 0.25.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache thrift < 0.25.0
Debian:12 debian thrift All versions
Ubuntu:20.04:LTS canonical thrift All versions
Original advisory text
DEBIAN-CVE-2026-83632
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-770Allocation of Resources Without Limits
CWE-190Integer Overflow
CWE-122Heap-based Buffer Overflow
Timeline
Published2 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Track software like this
Free during beta