Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-55969PATCHED
apache · thrift

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected Products

VendorProductVersions
apachethrift0, 0, 0, 0, 0, 0

References

  • https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9(vendor-advisory)
  • https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo(vendor-advisory)

Related News (2 articles)

Tier A
Microsoft MSRC1d ago
CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
→ No new info (linked only)
Tier B
CCCS Canada15d ago
Apache security advisory (AV26-749)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
0.24.0
CWECWE-190
PublishedJul 27, 2026
Last enriched15d ago
Trending Score42
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 87
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 56
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 51
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 43
HIGHCVE-2025-49506
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 27, 2026
Discovered by ZDM
Jul 27, 2026
Patch Available
Jul 27, 2026