Skip to content

Upgrade thrift module in vendor tarball of telegraf - #18291

Open
Kanishk-Bansal wants to merge 1 commit into
fasttrack/3.0from
kanbansal/telegraf-thrift
Open

Upgrade thrift module in vendor tarball of telegraf#18291
Kanishk-Bansal wants to merge 1 commit into
fasttrack/3.0from
kanbansal/telegraf-thrift

Conversation

@Kanishk-Bansal

@Kanishk-Bansal Kanishk-Bansal commented Aug 3, 2026

Copy link
Copy Markdown

Upgrade thrift module in vendor tarball of telegraf
Buddy Build - https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1174165&view=results
as 0.24.0 having fix for multiple CVEs, Hence it is better to go with the internal dependency upgrade solution instead of adding 20+ patches.

CVEs fixed in Thrift 0.24.0
CVE-2026-55971 — C++ heap buffer overflow (write) in THeaderTransport::untransform() — 9.3 Critical
CVE-2026-48144 — c_glib TLS client missing hostname verification — 9.1 Critical
CVE-2026-58662 — C++ THeaderTransport::readString() bounds bypass → OOB read — 9.1 Critical
CVE-2026-55969 — Integer overflow in TProtocol::checkReadBytesAvailable() (C++, c_glib, Go, netstd, Delphi, Haxe) — 8.7 High
CVE-2026-43871 — Infinite loop DoS (Python, Go, PHP, Java) — 8.7 High
CVE-2026-48145 — C++ TSSLSocket matchName() RFC 6125 wildcard bypass → MITM — 8.2 High
CVE-2026-55968 — Node.js quadratic-time DoS in server receive transports — 7.5 High
CVE-2026-41608 — Python zlib data amplification DoS — 7.5 High
CVE-2026-49158 — Ruby data amplification (highly compressed data) — 7.5 High
CVE-2026-48586 — TZlibTransport missing decompression size limit (C++, Java, Python, Go, D, c_glib) — High
CVE-2026-58389 — Rust allocation without limits/throttling — unrated
CVE-2026-45112 — Java unbounded read DoS (only 0.19.0 → <0.24.0) — 6.9 Medium
CVE-2026-58023 — c_glib heap OOB read in transport leftover-bytes path — 6.5 Medium
CVE-2026-55970 — C++ buffer over-read — 6.5 Medium
CVE-2026-66053 — Python cert host mismatch (replaces rejected CVE-2026-41603) — 5.9 Medium

@Kanishk-Bansal
Kanishk-Bansal requested a review from a team as a code owner August 3, 2026 06:45
@Kanishk-Bansal Kanishk-Bansal added security CVE-fixed-by-upgrade CVE fixed by package upgrade labels Aug 3, 2026
@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging fasttrack/3.0 PRs Destined for Azure Linux 3.0 labels Aug 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CVE-fixed-by-upgrade CVE fixed by package upgrade fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant