VYPR
High severity7.5NVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026

CVE-2026-43871

CVE-2026-43871

Description

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
thriftPyPI
< 0.24.00.24.0
github.com/apache/thriftGo
< 0.24.00.24.0
apache/thriftPackagist
< 0.24.00.24.0
org.apache.thrift:libthriftMaven
< 0.24.00.24.0

Affected products

139

Patches

Vulnerability mechanics

References

5

News mentions

1