CVE-2026-66055

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Credits

Bin Luo, University of Electronic Science and Technology of China (UESTC) (C++)
Apache Thrift Developers (Java/Go/netstd/Python/Delphi)

References