{"id":"CVE-2026-43871","title":"thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)","summary":"A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-835","vendor":"Red Hat","product":"Red Hat Hardened Images","affected":["enterprise_linux_ai_rhel_ai 3","openshift_update_service","hardened_images"],"patched":["hardened_images"],"published":"2026-07-27","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:35:41+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43871.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43871.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-43871"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507441"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-43871"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43871"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/24/33"},{"url":"https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9"},{"url":"https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby"},{"url":"https://access.redhat.com/errata/RHSA-2026:49837"},{"url":"https://github.com/apache/thrift"},{"url":"https://pypi.org/project/thrift"},{"url":"https://github.com/advisories/GHSA-8wv5-x4w7-5gww"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00607,"epssPercentile":0.47712,"aliases":["GHSA-8wv5-x4w7-5gww","BIT-thrift-2026-43871","PYSEC-2026-3926"],"ecosystem":"pip","ingestedAt":"2026-09-02T19:31:22.961Z","slug":"CVE-2026-43871","body":"## Overview\n\nA flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can trigger a continuous loop, leading to a denial of service (DoS) for applications using the affected bindings.\n\n## Vendor advisories\n\n- **RHSA-2026:49837** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49837)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Update Service · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Update Service · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43871.json)\n\n**thrift: Apache Thrift: Denial of Service via infinite loop** — rated Important by Red Hat. Released 2026-07-27, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift Update Service\n\nFixed:\n\n- Red Hat Hardened Images\n\nNo fix planned:\n\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift Update Service\n\nNot affected:\n\n- Confidential Compute Attestation\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49837\n\n## Package advisory (CVE-2026-43871)\n\nAffected packages:\n\n- `thrift < 0.24.0`\n- `github.com/apache/thrift < 0.24.0`\n- `apache/thrift < 0.24.0`\n- `org.apache.thrift:libthrift < 0.24.0`\n\nPatched in:\n\n- `thrift 0.24.0`\n- `github.com/apache/thrift 0.24.0`\n- `apache/thrift 0.24.0`\n- `org.apache.thrift:libthrift 0.24.0`\n\nSource: https://osv.dev/vulnerability/GHSA-8wv5-x4w7-5gww","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}