OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-82458

HIGH · CVSS 8.7 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to a memory allocation flaw that allows for excessive size values, potentially leading to resource exhaustion and denial of service. This high-severity vulnerability impacts multiple language bindings, including Java, and should be prioritized by organizations using affected versions to mitigate potential disruptions in service. Users are strongly advised to upgrade to version 0.25.0 to remediate this issue.

CVE
CVE-2026-82458
Severity
HIGH
CVSS
8.7
EPSS
0.43%
Apache Java

Original NVD Description

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.