


Perceptive Security
SOC/SIEM Consultancy

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to versio…
Published:
26 juli 2026 om 22:00:00
Alert date:
27 juli 2026 om 20:03:54
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
An out-of-bounds read vulnerability has been identified in Apache Thrift's c_glib bindings, tracked as CVE-2026-58023. All versions of Apache Thrift prior to 0.24.0 are affected by this issue. The vulnerability could allow attackers to read memory beyond allocated boundaries, potentially leading to information disclosure or application crashes. Apache has released version 0.24.0 to address and remediate the vulnerability. Users and administrators are strongly recommended to upgrade to Apache Thrift 0.24.0 immediately. The vulnerability was disclosed via Apache mailing lists and the Openwall security list. No workarounds are mentioned; upgrading is the sole recommended remediation. The issue specifically impacts the C GLib language binding of the Apache Thrift framework, which is used for cross-language service development.
Technical details
Mitigation steps:
Affected products:
Apache Thrift
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58023
https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
http://www.openwall.com/lists/oss-security/2026/07/24/43
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
