CyberRota Analysis
AI-GeneratedApache Thrift versions prior to 0.25.0 are vulnerable to an excessive iteration issue due to improper input validation and unbounded resource allocation, which could lead to denial-of-service attacks. Organizations utilizing Apache Thrift in their PHP applications should prioritize upgrading to version 0.25.0 to mitigate potential exploitation risks.
CVE
CVE-2026-91137
Severity
HIGH
CVSS
8.7
EPSS
0.43%
Apache
Original NVD Description
Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.