CVE-2026-91135

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-02); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-02: 1Mentions · 2026-10-03: 110-0210-03
Referenced assets1 URL
Full discourse2 posts
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Kritische Schwachstellen in Protokoll-Gateways und Apache Thrift: CVE-2026-86325 und CVE-2026-91135 #apachethrift #cve202686325 #cve202691135 #protokollgateways #theadertransport https://cybersecurity-news.de/kritische-schwachstellen-protokoll-gateways-apache-thrift-cve-2026-86325-cve-2026-91135

    0000011
    15 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-91135 Vendor → Unknown Severity → Critical — CVSS 9.2 Product → Unknown Date → 2026-10-02 A critical vulnerability (Heap-based Buffer Overflow) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000074
    437 followersView on X

Explore more