OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93925

HIGH · CVSS 8.7 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in the THeaderProtocol of Apache Thrift prior to version 0.25.0 can lead to potential remote code execution, posing a significant risk to applications utilizing this framework. Organizations using affected versions should prioritize upgrading to version 0.25.0 to mitigate the risk of exploitation. This is particularly critical for those with exposed services relying on Apache Thrift for communication.

CVE
CVE-2026-93925
Severity
HIGH
CVSS
8.7
EPSS
0.46%
Apache

Original NVD Description

Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.