{"id":"AZL-106533","summary":"CVE-2026-83663 affecting package telegraf 1.31.0-33","details":"Uncontrolled Recursion vulnerability in Apache Thrift go bindings.\n\n\n\nBoth Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","modified":"2026-10-08T05:35:32Z","published":"2026-10-02T13:17:58Z","upstream":["CVE-2026-83663"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83663"}],"affected":[{"package":{"name":"telegraf","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/telegraf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.31.0-33"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106533.json"}}],"schema_version":"1.9.0"}