Back to vendor advisories
Microsoft Security Response CenterCVE-2026-66055

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)

High 1 CVE Published Oct 4, 2026 at 1:02 AM UTC

Summary

Mariner

Products covered

  • azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0

  • azl3 kata-containers-cc 3.15.0.aks0-21 on Azure Linux 3.0

  • azl3 telegraf 1.31.0-33 on Azure Linux 3.0

  • azl3 thrift 0.24.0-1 on Azure Linux 3.0

Remediation

Release Notes

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Updated by Microsoft Security Response Center

    The vendor changed the advisory after it was first published.

  3. Added to SecurityAlert

    We collected the advisory from the official source.