You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7fc905b
Browse filesBrowse the repository at this point in the historyBrowse files
Apache Thrift 0.25.0 fixes a set of CVEs, including CVE-2026-66055
(unbounded resource allocation, affects the Python bindings) and
CVE-2026-66858 (missing recursion limit in protocol skip routines).
Downstream users whose vulnerability scanners block thrift 0.24.x
cannot upgrade without this change.
0.25.0 publishes the same prebuilt wheel set as 0.24.0 (manylinux2014,
musllinux, macOS and Windows, cp310-cp314), so the DBR LTS
install-safety reasoning from THRIFT-6067 still holds. Updated the
pyproject comment, moved the cap to <0.26.0 and regenerated
poetry.lock with Poetry 2.2.1.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017ZsYDtK7BMesAqaiBxpeFC
Signed-off-by: Thomas Tunc <28352452+thomastunc@users.noreply.github.com>
0 commit comments