Apache disclosed CVE-2026-55969, a high-severity integer overflow or wraparound vulnerability in TProtocol::checkReadBytesAvailable() that affects Apache Thrift versions before 0.24.0. The flaw was initially reported as impacting the C++ and c_glib bindings, and subsequent vulnerability reporting expanded the affected surface to include Go, netstd, Delphi, and Haxe bindings as well.
The vulnerability is rated CVSS 4.0 8.7 and is described as remotely exploitable, raising concern for applications that use vulnerable Thrift components to process untrusted input. Apache said users should upgrade to version 0.24.0 or later to remediate the issue; the bug was reported by Ghaith Abdulreda and Javid Khan and disclosed publicly by Jens Geyer.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-55969, an integer overflow or wraparound flaw in TProtocol::checkReadBytesAvailable() affecting Apache Thrift versions before 0.24.0. The disclosure said users should upgrade to version 0.24.0 to remediate the issue, and credited Ghaith Abdulreda and Javid Khan for reporting it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.