Apache Thrift 0.25.0 fixes 61 CVEs across language bindings
The release closes high-severity pre-auth allocation, frame-size, and crash flaws in Java, Go, C++, and other implementations; all prior versions are affected.
Apache Thrift 0.25.0, released 30 September 2026, fixes 61 vulnerabilities that affect every earlier release of the cross-language RPC framework. Maintainers recommend upgrading without delay.
Jens Geyer posted a combined notice on oss-security in place of 61 separate mailings. Each flaw was also announced on the Apache announce list and the Thrift user or dev lists on 1 October. Several carry high CVSS 4.0 scores and an ASF important rating.
Representative issues include an unauthenticated unbounded SASL frame allocation in the Java nonblocking SASL server (CVE-2026-61373, 8.7), a missing post-auth size limit on Java SASL data frames (CVE-2026-61374, 7.1), and an unauthenticated single-packet crash of Go Thrift servers through the THeader transform count (CVE-2026-63772, 8.7). C++ THeaderTransport failed to enforce the configured maximum frame size (CVE-2026-66054). TJSONProtocol accepted a single JSON string or number larger than the configured limit in C++, Java, Go, netstd, Python, and Delphi (CVE-2026-66055, 8.2).
The common thread is incomplete bounds checking on frames, headers, and protocol payloads. Consequences range from resource exhaustion to remote crashes, in some cases before any authentication. Because Thrift ships bindings for many languages, the same class of mistake often appears in more than one implementation; the 0.25.0 release is the point at which all of the listed defects are closed together.
Operators running any Thrift version before 0.25.0 should treat the upgrade as a security fix, especially for services exposed beyond a fully trusted network.