Hi Laszlo,
The following vulnerabilities were published for thrift, this is a
huge pile of CVEs and guess it is simply best to move to 0.25.0 for
unstable (not yet sure what we should do for trixie, but let's focus
first to make sure they get fixed for forky).
CVE-2026-61373[0]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in Apache Thrift Java TSaslNonblockingServer. This issue affects
| Apache Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-61374[1]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in Apache Thrift Java bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-63772[2]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in Apache Thrift go bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-66054[3]:
| Allocation of Resources Without Limits or Throttling, Improper
| Handling of Highly Compressed Data (Data Amplification)
| vulnerability in Apache Thrift C++ bindings. This issue affects
| Apache Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-66055[4]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-66081[5]:
| Access of Uninitialized Pointer vulnerability in Apache Thrift
| c_glib bindings. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-66837[6]:
| Stack-based Buffer Overflow, Integer Overflow or Wraparound
| vulnerability in Apache Thrift php bindings. This issue affects
| Apache Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-66858[7]:
| The protocol skip routine in several Apache Thrift bindings did not
| apply the binding's recursion limit, so a message that nests unknown
| fields deeply enough can exhaust the stack. Affected: the Python C++
| accelerator (the pure-Python protocols are not affected), the PHP
| library and its thrift_protocol extension, and the Perl, Lua,
| Smalltalk and OCaml libraries. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-66859[8]:
| NULL Pointer Dereference, Use of Uninitialized Variable
| vulnerability in Apache Thrift c_glib bindings. This issue
| affects Apache Thrift: before 0.25.0. Users are recommended to
| upgrade to version 0.25.0, which fixes the issue.
CVE-2026-82458[9]:
| Memory allocation with excessive size value, Allocation of resources
| without limits or throttling vulnerability in Apache Thrift
| Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D
| language bindings. This issue affects Apache Thrift: before
| 0.25.0. Users are recommended to upgrade to version 0.25.0, which
| fixes the issue.
CVE-2026-82459[10]:
| Integer underflow (wrap or wraparound), Out-of-bounds write
| vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This
| issue affects Apache Thrift: before 0.25.0. Users are recommended
| to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-83632[11]:
| Allocation of resources without limits or throttling, Integer
| overflow or wraparound, Heap-based buffer overflow vulnerability in
| Apache Thrift. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-83663[12]:
| Uncontrolled Recursion vulnerability in Apache Thrift go bindings.
| Both Go transports satisfy a read out of a buffered frame and, when
| that frame yields no payload bytes, read the next frame and call
| `Read` again instead of looping. A peer produces such a frame for 4
| bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in
| `THeaderTransport` (a header block that fills the frame), so nothing
| bounds the depth. The Go stack limit is reached as a `fatal error`,
| which `recover()` cannot catch, so the whole process dies. This
| issue affects Apache Thrift: before 0.25.0. Users are recommended
| to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85086[13]:
| Improper certificate validation, Initialization of a resource with
| an insecure default vulnerability in Apache Thrift perl bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85087[14]:
| Improper certificate validation, Return of wrong status code
| vulnerability in Apache Thrift python bindings. This issue
| affects Apache Thrift: before 0.25.0. Users are recommended to
| upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85088[15]:
| Improper Validation of Certificate with Host Mismatch in the C++ and
| D libraries of Apache Thrift. Both libraries install a default
| access manager for client sockets — TSSLSocketFactory does so in
| C++, and the accessManager property does so in D — which compares
| the peer certificate against the host name that was connected to.
| That comparison walks the subjectAltName dNSName entries first and
| consults the certificate Common Name afterwards. A name that does
| not match yields a "skip" result rather than a rejection, so a
| certificate whose subjectAltName entries are all present and all
| non-matching falls through to the Common Name, which can then
| satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section
| 2, require that the Common Name is not consulted when a dNSName
| subjectAltName is present. A certificate carrying subjectAltName
| entries for one name and a Common Name for another is therefore
| accepted for a connection to the second name. Exploitation
| requires an attacker positioned on the network path who holds a
| certificate that chains to a certificate authority in the client's
| trust store and whose Common Name matches the connected host name.
| Public certificate authorities have not issued on Common Name alone
| for many years, so this is principally a concern for deployments
| using a private or enterprise public-key infrastructure. This
| issue affects the C++ library of Apache Thrift from 0.7.0 through
| 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should
| upgrade to 0.25.0.
CVE-2026-85476[16]:
| Loop with unreachable exit condition ('infinite loop') vulnerability
| in Apache Thrift c_glib bindings. This issue affects Apache
| Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-85483[17]:
| Use of uninitialized resource, Return of wrong status code
| vulnerability in Apache Thrift c_glib bindings. This issue
| affects Apache Thrift: before 0.25.0. Users are recommended to
| upgrade to version 0.25.0, which fixes the issue.
CVE-2026-85494[18]:
| Improper handling of length parameter inconsistency, Uncaught
| exception, Inefficient Algorithmic Complexity, Memory allocation
| with excessive size value, Initialization of a resource with an
| insecure default vulnerability in Apache Thrift Python, Ruby,
| Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-91135[19]:
| Heap-based buffer overflow vulnerability in Apache Thrift C++
| THeaderTransport. When an application enables the ZLIB transform
| for the frames it sends, THeaderTransport::transform() copies the
| compressed frame into the write buffer without making sure it fits.
| Data that does not compress, such as content a remote peer supplied,
| grows under compression, so the copy writes past the end of the heap
| buffer by an amount that grows with the size of the frame, and for
| large frames it also reads past the end of the transform buffer.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-91137[20]:
| Improper validation of specified quantity in input, Allocation of
| resources without limits or throttling, Excessive Iteration
| vulnerability in Apache Thrift PHP bindings. This issue affects
| Apache Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-92834[21]:
| Use of uninitialized resource, Return of wrong status code
| vulnerability in Apache Thrift C++ WebSocket server. This issue
| affects Apache Thrift: before 0.25.0. Users are recommended to
| upgrade to version 0.25.0, which fixes the issue.
CVE-2026-93925[22]:
| Stack-based buffer overflow, Incorrect bitwise shift of integer
| vulnerability in Apache Thrift C++ THeaderProtocol. This issue
| affects Apache Thrift: before 0.25.0. Users are recommended to
| upgrade to version 0.25.0, which fixes the issue.
CVE-2026-93926[23]:
| Missing release of memory after effective lifetime, Missing release
| of resource after effective lifetime vulnerability in Apache Thrift
| THeaderTransport. This issue affects Apache Thrift: before
| 0.25.0. Users are recommended to upgrade to version 0.25.0, which
| fixes the issue.
CVE-2026-94634[24]:
| Allocation of resources without limits or throttling, Initialization
| of a resource with an insecure default vulnerability in Apache
| Thrift Python bindings. This issue affects Apache Thrift: before
| 0.25.0. Users are recommended to upgrade to version 0.25.0, which
| fixes the issue.
CVE-2026-94636[25]:
| Improper handling of highly compressed data (data amplification),
| Function call with incorrectly specified arguments, Improper
| validation of specified quantity in input vulnerability in Apache
| Thrift py bindings. This issue affects Apache Thrift: before
| 0.25.0. Users are recommended to upgrade to version 0.25.0, which
| fixes the issue.
CVE-2026-94637[26]:
| Improper handling of highly compressed data (data amplification)
| vulnerability in Apache Thrift Go bindings. This issue affects
| Apache Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-94638[27]:
| Allocation of resources without limits or throttling vulnerability
| in Apache Thrift PHP bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-94639[28]:
| improper handling of exceptional conditions, Allocation of resources
| without limits or throttling, Uncaught exception vulnerability in
| Apache Thrift Java bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-94642[29]:
| Uncaught exception vulnerability in Apache Thrift PHP bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94644[30]:
| Allocation of resources without limits or throttling vulnerability
| in Apache Thrift PHP bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-94650[31]:
| Uncontrolled Recursion vulnerability in Apache Thrift c_glib
| bindings. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-94651[32]:
| improper handling of exceptional conditions, Missing release of
| resource after effective lifetime vulnerability in Apache Thrift
| java bindings. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-94652[33]:
| Missing release of memory after effective lifetime vulnerability in
| Apache Thrift c++ bindings. This issue affects Apache Thrift:
| before 0.25.0. Users are recommended to upgrade to version
| 0.25.0, which fixes the issue.
CVE-2026-94653[34]:
| Inefficient Algorithmic Complexity vulnerability in Apache Thrift
| PHP bindings. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-94654[35]:
| Loop with unreachable exit condition ('infinite loop') vulnerability
| in Apache Thrift python bindings. This issue affects Apache
| Thrift: before 0.25.0. Users are recommended to upgrade to
| version 0.25.0, which fixes the issue.
CVE-2026-96286[36]:
| Uncaught exception vulnerability in Apache Thrift Perl bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-96287[37]:
| Inefficient Algorithmic Complexity vulnerability in Apache Thrift
| Perl bindings. This issue affects Apache Thrift: before 0.25.0.
| Users are recommended to upgrade to version 0.25.0, which fixes the
| issue.
CVE-2026-96289[38]:
| Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.
| This issue affects Apache Thrift: before 0.25.0. Users are
| recommended to upgrade to version 0.25.0, which fixes the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-61373
https://www.cve.org/CVERecord?id=CVE-2026-61373
[1] https://security-tracker.debian.org/tracker/CVE-2026-61374
https://www.cve.org/CVERecord?id=CVE-2026-61374
[2] https://security-tracker.debian.org/tracker/CVE-2026-63772
https://www.cve.org/CVERecord?id=CVE-2026-63772
[3] https://security-tracker.debian.org/tracker/CVE-2026-66054
https://www.cve.org/CVERecord?id=CVE-2026-66054
[4] https://security-tracker.debian.org/tracker/CVE-2026-66055
https://www.cve.org/CVERecord?id=CVE-2026-66055
[5] https://security-tracker.debian.org/tracker/CVE-2026-66081
https://www.cve.org/CVERecord?id=CVE-2026-66081
[6] https://security-tracker.debian.org/tracker/CVE-2026-66837
https://www.cve.org/CVERecord?id=CVE-2026-66837
[7] https://security-tracker.debian.org/tracker/CVE-2026-66858
https://www.cve.org/CVERecord?id=CVE-2026-66858
[8] https://security-tracker.debian.org/tracker/CVE-2026-66859
https://www.cve.org/CVERecord?id=CVE-2026-66859
[9] https://security-tracker.debian.org/tracker/CVE-2026-82458
https://www.cve.org/CVERecord?id=CVE-2026-82458
[10] https://security-tracker.debian.org/tracker/CVE-2026-82459
https://www.cve.org/CVERecord?id=CVE-2026-82459
[11] https://security-tracker.debian.org/tracker/CVE-2026-83632
https://www.cve.org/CVERecord?id=CVE-2026-83632
[12] https://security-tracker.debian.org/tracker/CVE-2026-83663
https://www.cve.org/CVERecord?id=CVE-2026-83663
[13] https://security-tracker.debian.org/tracker/CVE-2026-85086
https://www.cve.org/CVERecord?id=CVE-2026-85086
[14] https://security-tracker.debian.org/tracker/CVE-2026-85087
https://www.cve.org/CVERecord?id=CVE-2026-85087
[15] https://security-tracker.debian.org/tracker/CVE-2026-85088
https://www.cve.org/CVERecord?id=CVE-2026-85088
[16] https://security-tracker.debian.org/tracker/CVE-2026-85476
https://www.cve.org/CVERecord?id=CVE-2026-85476
[17] https://security-tracker.debian.org/tracker/CVE-2026-85483
https://www.cve.org/CVERecord?id=CVE-2026-85483
[18] https://security-tracker.debian.org/tracker/CVE-2026-85494
https://www.cve.org/CVERecord?id=CVE-2026-85494
[19] https://security-tracker.debian.org/tracker/CVE-2026-91135
https://www.cve.org/CVERecord?id=CVE-2026-91135
[20] https://security-tracker.debian.org/tracker/CVE-2026-91137
https://www.cve.org/CVERecord?id=CVE-2026-91137
[21] https://security-tracker.debian.org/tracker/CVE-2026-92834
https://www.cve.org/CVERecord?id=CVE-2026-92834
[22] https://security-tracker.debian.org/tracker/CVE-2026-93925
https://www.cve.org/CVERecord?id=CVE-2026-93925
[23] https://security-tracker.debian.org/tracker/CVE-2026-93926
https://www.cve.org/CVERecord?id=CVE-2026-93926
[24] https://security-tracker.debian.org/tracker/CVE-2026-94634
https://www.cve.org/CVERecord?id=CVE-2026-94634
[25] https://security-tracker.debian.org/tracker/CVE-2026-94636
https://www.cve.org/CVERecord?id=CVE-2026-94636
[26] https://security-tracker.debian.org/tracker/CVE-2026-94637
https://www.cve.org/CVERecord?id=CVE-2026-94637
[27] https://security-tracker.debian.org/tracker/CVE-2026-94638
https://www.cve.org/CVERecord?id=CVE-2026-94638
[28] https://security-tracker.debian.org/tracker/CVE-2026-94639
https://www.cve.org/CVERecord?id=CVE-2026-94639
[29] https://security-tracker.debian.org/tracker/CVE-2026-94642
https://www.cve.org/CVERecord?id=CVE-2026-94642
[30] https://security-tracker.debian.org/tracker/CVE-2026-94644
https://www.cve.org/CVERecord?id=CVE-2026-94644
[31] https://security-tracker.debian.org/tracker/CVE-2026-94650
https://www.cve.org/CVERecord?id=CVE-2026-94650
[32] https://security-tracker.debian.org/tracker/CVE-2026-94651
https://www.cve.org/CVERecord?id=CVE-2026-94651
[33] https://security-tracker.debian.org/tracker/CVE-2026-94652
https://www.cve.org/CVERecord?id=CVE-2026-94652
[34] https://security-tracker.debian.org/tracker/CVE-2026-94653
https://www.cve.org/CVERecord?id=CVE-2026-94653
[35] https://security-tracker.debian.org/tracker/CVE-2026-94654
https://www.cve.org/CVERecord?id=CVE-2026-94654
[36] https://security-tracker.debian.org/tracker/CVE-2026-96286
https://www.cve.org/CVERecord?id=CVE-2026-96286
[37] https://security-tracker.debian.org/tracker/CVE-2026-96287
https://www.cve.org/CVERecord?id=CVE-2026-96287
[38] https://security-tracker.debian.org/tracker/CVE-2026-96289
https://www.cve.org/CVERecord?id=CVE-2026-96289
Regards,
Salvatore