CVE-2026-82458

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Referenced assets1 URL
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - Apache Thrift Unbounded Memory Allocation DoS (CVE-2026-82458) Apache Thrift language bindings fail to cap size fields during deserialization, allowing a remote client to send an excessively large length value and trigger unbounded memory allocation (no throttling) leading to process OOM and denial of service. Only versions < 0.25.0 are impacted. 👉Affected: Apache Thrift (libthrift / http://github.com/apache/thrift / ApacheThrift / org.apache.thrift:libthrift) < 0.25.0 | Upgrade to 0.25.0

    0000067
    308 followersView on X

Explore more