High severityNVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-83663
CVE-2026-83663
Description
Uncontrolled Recursion vulnerability in Apache Thrift go bindings.
Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call Read again instead of looping. A peer produces such a frame for 4 bytes in TFramedTransport (a declared size of zero) or 18 bytes in THeaderTransport (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a fatal error, which recover() cannot catch, so the whole process dies.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.