OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-61374

HIGH · CVSS 7.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift Java bindings prior to version 0.25.0 are vulnerable to an allocation of resources without limits or throttling, potentially leading to resource exhaustion and denial of service. Organizations utilizing affected versions should prioritize upgrading to 0.25.0 to mitigate this high-severity risk. This vulnerability is particularly critical for developers and system administrators managing applications that rely on Apache Thrift.

CVE
CVE-2026-61374
Severity
HIGH
CVSS
7.1
EPSS
0.24%
Apache Java

Original NVD Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.