APACHE Thrift has released version 0.25.0 on 2 October 2026, addressing 61 vulnerabilities across its framework and bindings. The release notes describe a broad set of issues, with two critical flaws and the remainder spanning high and medium severity. The most serious defects are CVSS 9.2-rated heap overflows and related memory issues that can occur without authentication, underscoring the need for a comprehensive upgrade across affected deployments.
The TL;DR of the advisory notes that although the flaws affect multiple language bindings (C++, Java, Go, Python, PHP, Node[.]js, Ruby, Erlang, and others), there is no publicly confirmed exploitation at the time of the write‑up.
Key CVEs highlighted include CVE-2026-91135 (C++ THeaderTransport heap buffer overflow when ZLIB is enabled) and CVE-2026-83632 (a heap overflow combining unlimited resource allocation with an integer overflow). Additional entries cover pre-auth unbounded SASL frame allocation in Java TSaslNonblockingServer (CVE-2026-61373), and Go-specific issues such as unauthenticated single-packet crashes linked to the THeader transform count (CVE-2026-63772).
The advisory also notes certificate‑checking weaknesses (CVE-2026-85088) affecting C++ and D libraries in some private/public PKI deployments, along with various memory and recursion-related bugs across bindings. The article states all 61 flaws affected versions prior to 0.25.0, with many dating back several years.
Practical response recommended is straightforward: upgrade all Thrift libraries and generated services to Apache Thrift 0.25.0, and rebuild applications that bundle Thrift. Until patches are applied, operators are advised to isolate Thrift endpoints from untrusted networks and enforce message size limits where supported.