CVE-2026-83663 PUBLISHED

Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)

Assigner: apache
Reserved: 31.08.2026 Published: 02.10.2026 Updated: 02.10.2026

Uncontrolled Recursion vulnerability in Apache Thrift go bindings.

Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call Read again instead of looping. A peer produces such a frame for 4 bytes in TFramedTransport (a declared size of zero) or 18 bytes in THeaderTransport (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a fatal error, which recover() cannot catch, so the whole process dies.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Apache Software Foundation
Product Apache Thrift
Versions Default: unaffected
  • affected from 0 to 0.25.0 (excl.)

Credits

  • Ho1aAs <xxy010605@gmail.com> for TFramedTransport finder
  • Apache Thrift Developers for THeaderTransport finder

References

Problem Types

  • CWE-674 Uncontrolled Recursion CWE