Data Amplification Affecting github.com/apache/thrift/lib/go/thrift package, versions <0.25.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.43% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMAPACHETHRIFTLIBGOTHRIFT-20510274
  • published5 Oct 2026
  • disclosed2 Oct 2026
  • creditUnknown

Introduced: 2 Oct 2026

NewCVE-2026-94637  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

Upgrade github.com/apache/thrift/lib/go/thrift to version 0.25.0 or higher.

Overview

github.com/apache/thrift/lib/go/thrift is a Go implementation of the Apache Thrift library.

Affected versions of this package are vulnerable to Data Amplification in THeaderTransport.parseHeaders() in lib/go/thrift/header_transport.go, which attaches a ZLIB reader to the frame whenever the header block lists that transform and places no bound on the inflated output, although ReadFrame already holds the frame itself to MaxFrameSize as it comes off the wire. An attacker can exhaust the process memory by sending a frame that stays within the wire size limit but whose ZLIB payload inflates far beyond it. This requires the application to use the Go bindings with THeaderTransport, and the transform is selected per frame by the sender in the header block rather than by the receiving application's configuration, so an application that never enables ZLIB itself still inflates frames that ask for it.

CVSS Base Scores

version 4.0
version 3.1