OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-83632

CRITICAL · CVSS 9.2 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to a critical heap-based buffer overflow due to improper resource allocation, which can lead to arbitrary code execution. Organizations utilizing affected versions should prioritize upgrading to 0.25.0 to mitigate the risk of exploitation. This vulnerability poses a significant threat, particularly for those deploying Apache Thrift in production environments.

CVE
CVE-2026-83632
Severity
CRITICAL
CVSS
9.2
EPSS
0.38%
Apache

Original NVD Description

Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.