CVE-2026-55969
Serial Number: AV26-749 Date: July 28, 2026 As of July 27, 2026, Apache is affected by vulnerabilities in the following product: Apache Thrift Prior to 0.24.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
CSIRTS triage
- What
- Apache Thrift has multiple vulnerabilities related to decompression and integer overflow.
- Who is affected
- Users of Apache Thrift prior to version 0.24.0 are affected.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to various issues, although exploitation status is currently unknown.
- Action
- Users should update to Apache Thrift version 0.24.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-55969
Get an email if CVE-2026-55969 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk1.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownApache security advisory (AV26-749)cccs · 2026-07-28
- highCVE-2026-55969: Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi …nvd · 2026-07-27
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55969)