Apache Thrift TFramedTransport Go Integer Overflow Vulnerability

Vulnerability

An integer overflow vulnerability has been identified in the Go language implementation of Apache Thrift's TFramedTransport, affecting versions prior to 0.23.0. This vulnerability could potentially be exploited, leading to undefined behavior or other unintended consequences.

Impact

Exploitation of this vulnerability could lead to an integer overflow, allowing for potential memory corruption or other unintended behavior in the application.

Remediation

Users are advised to upgrade to Apache Thrift version 0.23.0 or later, which addresses this vulnerability.

Added: Apr 28, 2026, 10:40 AM
Updated: Apr 28, 2026, 10:40 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
7.4
remediation
7.7
relevance
6.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.