Apache Thrift Loop: Unreachable Exit in Bindings v<0.24.0
CVE-2026-43871 Published on July 27, 2026

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor Advisory Vendor Advisory NVD

Weakness Type

What is an Infinite Loop Vulnerability?

The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.

CVE-2026-43871 has been classified to as an Infinite Loop vulnerability or weakness.


Products Associated with CVE-2026-43871

Want to know whenever a new CVE is published for Apache Thrift? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Thrift: Apache Software Foundation Apache Thrift: Apache Software Foundation Apache Thrift: Apache Software Foundation Apache Thrift: