Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-91135

CVE-2026-91135: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityCritical9.2

    Critical [CVE-2026-91135] Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport

    CVE-2026-91135Source published Source updated

    Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the heap buffer by an amount that grows with the size of the frame, and for large frames it also reads past the end of the transform buffer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

    Affected products in this advisory
    • Apache Thrift
    Source-reported affected versions
    • Apache Thrift before 0.25.0
    Source-reported fixed versions
    • 0.25.0
    Mitigation guidance
    • Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery