CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds ad in THeaderTransport::adHeaderFormat()
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Apache Thrift
CVE-2026-55970 has been classified as a high-severity vulnerability due to its potential for triggering heap out-of-bounds writes.
To fix CVE-2026-55970, you should upgrade to the latest version of Apache Thrift that contains the security patch addressing this vulnerability.
CVE-2026-55970 affects all versions of Apache Thrift, specifically those utilizing the C++ implementation.
Exploiting CVE-2026-55970 may allow an attacker to execute arbitrary code or crash the application due to memory corruption.
CVE-2026-55970 was published on July 24, 2026.