ghsa-8wv5-x4w7-5gww

CVSS 8.7 osv_packagist
Description

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8wv5-x4w7-5gww/GHSA-8wv5-x4w7-5gww.json"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "thrift",
        "purl": "pkg:pypi/thrift"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.24.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "0.10.0",
        "0.11.0",
        "0.13.0",
        "0.14.0",
        "0.14.1",
        "0.14.2",
        "0.15.0",
        "0.16.0",
        "0.20.0",
        "0.21.0",
        "0.22.0",
        "0.23.0",
        "0.8.0",
        "0.9.0",
        "0.9.1",
        "0.9.2",
        "0.9.3"
      ]
    },
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8wv5-x4w7-5gww/GHSA-8wv5-x4w7-5gww.json"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/apache/thrift",
        "purl": "pkg:golang/github.com/apache/thrift"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.24.0"
            }
          ],
          "type": "SEMVER"
        }
      ]
    },
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8wv5-x4w7-5gww/GHSA-8wv5-x4w7-5gww.json"
      },
      "package": {
        "ecosystem": "Packagist",
        "name": "apache/thrift",
        "purl": "pkg:composer/apache/thrift"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.24.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "0.10.0",
        "0.11.0",
        "0.9.0",
        "0.9.2",
        "0.9.3",
        "0.9.3.1",
        "v0.12.0",
        "v0.13.0",
        "v0.14.0",
        "v0.14.1",
        "v0.14.2",
        "v0.15.0",
        "v0.16.0",
        "v0.17.0",
        "v0.18.0",
        "v0.18.1",
        "v0.19.0",
        "v0.20.0",
        "v0.21.0",
        "v0.22.0",
        "v0.23.0"
      ]
    },
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8wv5-x4w7-5gww/GHSA-8wv5-x4w7-5gww.json"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.apache.thrift:libthrift",
        "purl": "pkg:maven/org.apache.thrift/libthrift"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.24.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "0.10.0",
        "0.11.0",
        "0.12.0",
        "0.13.0",
        "0.14.0",
        "0.14.1",
        "0.14.2",
        "0.15.0",
        "0.16.0",
        "0.17.0",
        "0.18.0",
        "0.18.1",
        "0.19.0",
        "0.20.0",
        "0.21.0",
        "0.22.0",
        "0.23.0",
        "0.6.1",
        "0.7.0",
        "0.8.0",
        "0.9.0",
        "0.9.1",
        "0.9.2",
        "0.9.3",
        "0.9.3-1"
      ]
    }
  ],
  "aliases": [
    "BIT-thrift-2026-43871",
    "CVE-2026-43871",
    "PYSEC-2026-3926"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-835"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-02T14:31:01Z",
    "nvd_published_at": "2026-07-27T12:16:44Z",
    "severity": "HIGH"
  },
  "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.",
  "id": "GHSA-8wv5-x4w7-5gww",
  "modified": "2026-09-10T12:25:42.392618810Z",
  "published": "2026-07-27T12:31:16Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/apache/thrift"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9"
    },
    {
      "type": "WEB",
      "url": "https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/07/24/33"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop"
}
View JSON API Download JSON