Executive Summary: Core Cloud RPC Framework Vulnerable to Heap Overflow

The Apache Software Foundation has released a critical security bulletin detailing an exploitable heap-based memory corruption vulnerability in Apache Thrift, the foundational cross-language remote procedure call (RPC) framework utilized across cloud hyperscalers, distributed database architectures, and financial messaging meshes. Tracked under CVE-2026-91135 and documented in GitHub security advisory GHSA-3gv9-wqfp-2rf3, the vulnerability carries a Critical severity designation and impacts all Apache Thrift C++ implementations prior to version 0.25.0.

The defect resides inside THeaderTransport::transform(), the C++ transport layer routine responsible for applying compression transforms—specifically the ZLIB algorithm—to incoming and outgoing RPC frame buffers. Because the implementation relies on an inaccurate assumption regarding compressed data expansion bounds, an unauthenticated network adversary submitting specially constructed RPC payloads can force the transport buffer to write arbitrarily past allocated heap chunks, inducing remote code execution (RCE) with the operational privileges of the target microservice.

Vulnerability Mechanics: ZLIB Expansion and Write Buffer Out-of-Bounds

Under the Apache Thrift header transport protocol (THeaderTransport), message payloads can be encapsulated with metadata headers and passed through optional transform filters such as compression. When an application enables the ZLIB transform, THeaderTransport::transform() compresses the frame content before dispatching it across the wire:

// Vulnerable implementation logic in THeaderTransport.cpp (prior to 0.25.0):
void THeaderTransport::transform(uint8_t* in, uint32_t in_len, uint8_t* out, uint32_t& out_len) {
    if (transform_type == ZLIB_TRANSFORM) {
        z_stream stream;
        // Inadequate destination buffer size calculation:
        // When input data is already high-entropy or random bytes, ZLIB output can
        // exceed input length (deflate expansion overhead):
        deflateInit(&stream, Z_DEFAULT_COMPRESSION);
        stream.next_in = in;
        stream.avail_in = in_len;
        stream.next_out = out;
        stream.avail_out = writeBufferSize_; // Fixed destination boundary!

        deflate(&stream, Z_FINISH);
        out_len = stream.total_out;

        // VULNERABILITY: THeaderTransport copies the transformed frame into writeBuffer_
        // without ensuring total_out <= writeBufferSize_:
        memcpy(writeBuffer_.get(), out, out_len); // Heap buffer overflow!
        deflateEnd(&stream);
    }
}

When a remote peer sends input containing incompressible, high-entropy binary structures (e.g., pre-encrypted cryptographic ciphertext or compressed image blobs), the standard DEFLATE algorithm encounters an expansion penalty due to non-compressible block headers (RFC 1951). Because THeaderTransport failed to recalculate boundary buffers using deflateBound(), the compressed frame grows beyond the fixed destination write buffer. The subsequent memory copy writes past the allocated boundary in the process heap, corrupting adjacent metadata chunks and, for large payloads, triggering an out-of-bounds read past the transform buffer as well.

Microservices Impact & Lateral Movement Blast Radius

Because Apache Thrift serves as the low-latency inter-process communication backbone in distributed microservice topologies, exploitation exposes critical core systems:

Target Architectural Tier Attack Vector Operational Impact
API Gateways & Ingress Proxies External Malformed RPC Call Edge gateway crash; arbitrary execution in the demilitarized zone (DMZ).
Distributed Databases & Caches Inter-node Replication Frame Corrupts memory allocations on storage coordinator nodes, inducing state desynchronization.
Internal Microservices Mesh Lateral East-West RPC Traffic Pivot from a compromised low-privilege pod to sensitive internal banking/payment microservices.

Defensive Remediation Checklist

  1. Upgrade to Apache Thrift 0.25.0: Transition all microservice dependencies and C++ services to release 0.25.0, which properly bounds ZLIB transform buffers using deflateBound() and enforces strict length validation.
  2. Disable ZLIB Transform in Transport Configuration: If immediate binary upgrades cannot be scheduled, disable the ZLIB transform across service definitions:
    // Temporary code-level mitigation:
    // Explicitly remove ZLIB transforms from THeaderTransport instances:
    headerTransport->setTransform(0); // Clear transform flags
  3. Enforce Ingress RPC Payload Inspection: Configure ingress firewalls and Envoy/Istio service meshes to enforce maximum frame sizes on Thrift TCP ports (e.g., port 9090) to prevent oversized payloads from reaching vulnerable endpoints.