
🚨High - Apache Thrift Unbounded Memory Allocation DoS (CVE-2026-82458) Apache Thrift language bindings fail to cap size fields during deserialization, allowing a remote client to send an excessively large length value and trigger unbounded memory allocation (no throttling) leading to process OOM and denial of service. Only versions < 0.25.0 are impacted. 👉Affected: Apache Thrift (libthrift / http://github.com/apache/thrift / ApacheThrift / org.apache.thrift:libthrift) < 0.25.0 | Upgrade to 0.25.0
