Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-91135: Apache Thrift can overflow memory when using compression
CVE-2026-91135 · published 8 days ago
Summary
Versions of Apache Thrift prior to 0.25.0 may write beyond their allocated memory when the ZLIB compression option is used, which can cause crashes or allow an attacker to take control. This happens because the program does not check that the compressed data fits into the buffer. Upgrade to Thrift version 0.25.0 or later to resolve the issue.
What to do
- Update apache software foundation apache thrift to version 0.25.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache thrift | < 0.25.0 |
| Debian:12 | debian | thrift | All versions |
| Ubuntu:20.04:LTS | canonical | thrift | All versions |
Original advisory text
DEBIAN-CVE-2026-91135
Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.
When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/rbpwlhlxnv2qgyk8cfscp2d2fd3p0ojb
- https://security-tracker.debian.org/tracker/CVE-2026-91135 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-91135 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-91135 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published2 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Sources
CVE-2026-91135 · NVD
CVE-2026-91135 · MITRE
DEBIAN-CVE-2026-91135 · OSV
UBUNTU-CVE-2026-91135 · OSV
Track software like this
Free during beta