CVE-2026-83663
Received Received - Intake

Uncontrolled Recursion in Apache Thrift Go Bindings

Vulnerability report for CVE-2026-83663, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Uncontrolled Recursion vulnerability in Apache Thrift's Go bindings. The issue occurs when Go transports read a buffered frame that yields no payload bytes. Instead of looping, they call Read again, leading to unbounded recursion depth. A malicious peer can exploit this by sending specific frame sizes (4 bytes for TFramedTransport or 18 bytes for THeaderTransport) to crash the process by hitting the Go stack limit, which cannot be recovered from.

Detection Guidance

This vulnerability causes a fatal error in Go processes using Apache Thrift before 0.25.0 due to uncontrolled recursion. Check if your system runs affected Thrift versions with commands like 'go list -m github.com/apache/thrift' or inspect process logs for fatal errors related to stack overflow.

Impact Analysis

This vulnerability can cause a denial of service by crashing the affected process. If your application uses Apache Thrift's Go bindings before version 0.25.0, an attacker could send specially crafted frames to trigger the recursion and terminate your service, leading to downtime or service unavailability.

Compliance Impact

This vulnerability causes a denial-of-service by crashing the process, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing. For HIPAA, it could interrupt systems managing protected health information. Compliance may be affected if service disruptions lead to unauthorized access or data breaches.

Mitigation Strategies

Upgrade Apache Thrift Go bindings to version 0.25.0 or later to fix the uncontrolled recursion issue. Stop affected services temporarily if upgrading immediately is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83663. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart