CVE-2026-83663
ADVISORY - nistSummary
Uncontrolled Recursion vulnerability in Apache Thrift go bindings.
Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call Read again instead of looping. A peer produces such a frame for 4 bytes in TFramedTransport (a declared size of zero) or 18 bytes in THeaderTransport (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a fatal error, which recover() cannot catch, so the whole process dies.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-83663
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.7highDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-83663
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Red Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-83663
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)