CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift
CVE-2026-55971 is rated as critical due to the potential for remote code execution through a heap buffer overflow.
To fix CVE-2026-55971, update to the patched version of Apache Thrift that addresses this vulnerability.
CVE-2026-55971 affects earlier versions of Apache Thrift prior to the release that contains the security fix.
Exploitation of CVE-2026-55971 may allow an attacker to execute arbitrary code on the affected system.
A workaround for CVE-2026-55971 involves restricting access to the THeaderTransport service to trusted networks.