OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-91137

HIGH · CVSS 8.7 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to an excessive iteration issue due to improper input validation and unbounded resource allocation, which could lead to denial-of-service attacks. Organizations utilizing Apache Thrift in their PHP applications should prioritize upgrading to version 0.25.0 to mitigate potential exploitation risks.

CVE
CVE-2026-91137
Severity
HIGH
CVSS
8.7
EPSS
0.43%
Apache

Original NVD Description

Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.