OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-66859

HIGH · CVSS 8.7 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to a NULL Pointer Dereference and Use of Uninitialized Variable, which could lead to application crashes or unexpected behavior. Organizations utilizing Apache Thrift in their systems should prioritize upgrading to version 0.25.0 to mitigate potential exploitation risks associated with this high-severity vulnerability.

CVE
CVE-2026-66859
Severity
HIGH
CVSS
8.7
EPSS
0.43%
Apache

Original NVD Description

NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.