CVE-2026-58662: Apache Thrift: C++ THeaderTransport::adString() info-header length bounds bypass
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Apache Thrift
CVE-2026-58662 has been classified as a medium severity vulnerability.
To fix CVE-2026-58662, update Apache Thrift to the latest version that addresses this vulnerability.
CVE-2026-58662 may allow an attacker to bypass length validation checks, leading to information disclosure or application crashes.
CVE-2026-58662 affects specific older versions of Apache Thrift prior to the fix published on July 24, 2026.
Yes, CVE-2026-58662 could potentially be exploited remotely if an attacker can send crafted requests to the affected Apache Thrift service.