CVE-2026-43871High· 7.5▾ TwilightA flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can trigger a continuous loop, leading to a denial of service (DoS) for applications using the affected bindings.
thrift: Apache Thrift: Denial of Service via infinite loop — rated Important by Red Hat. Released 2026-07-27, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:49837
Affected packages:
thrift < 0.24.0github.com/apache/thrift < 0.24.0apache/thrift < 0.24.0org.apache.thrift:libthrift < 0.24.0Patched in:
thrift 0.24.0github.com/apache/thrift 0.24.0apache/thrift 0.24.0org.apache.thrift:libthrift 0.24.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27628High· 7.5pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)
CVE-2025-69227High· 7.5aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2020-14040High· 7.5golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)
CVE-2026-56852High· 7.5golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852)
CVE-2026-40575High· 8.7oauth2-proxy: github.com/oauth2-proxy/oauth2-proxy: OAuth2 Proxy: Authentication bypass due to spoofed X-Forwarded-Uri header (CVE-2026-405…