CVE-2026-83745 - Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)
CVE ID :CVE-2026-83745 Published : Oct. 2, 2026, 1:17 p.m. | 2 hours, 2 minutes ago Description :Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server...