CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift
CVE-2026-58389 is rated as a medium severity vulnerability.
To fix CVE-2026-58389, users should update to the latest version of Apache Thrift that includes the fix for the Rust binary protocol.
CVE-2026-58389 affects Apache Thrift implementations that utilize the Rust binary protocol.
CVE-2026-58389 is a vulnerability related to a non-strict path and missing string size limit.
The potential impacts of CVE-2026-58389 include application crashes and possible denial of service due to improper handling of string sizes.