VYPR
High severityNVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026

CVE-2026-83663

CVE-2026-83663

Description

Uncontrolled Recursion vulnerability in Apache Thrift go bindings.

Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call Read again instead of looping. A peer produces such a frame for 4 bytes in TFramedTransport (a declared size of zero) or 18 bytes in THeaderTransport (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a fatal error, which recover() cannot catch, so the whole process dies.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.