SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-43871

HIGH · CVSS 7.5 EPSS 0.61%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.24.0 are vulnerable to an infinite loop condition in the Python, Go, PHP, and Java bindings, which can lead to denial of service by causing applications to hang indefinitely. Organizations using these affected bindings should prioritize upgrading to version 0.24.0 to mitigate potential disruptions in service. This vulnerability poses a significant risk, particularly for systems relying on Apache Thrift for inter-service communication.

CVE
CVE-2026-43871
Severity
HIGH
CVSS
7.5
EPSS
0.61%
Apache Java

Original NVD Description

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)