OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94636

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to improper handling of highly compressed data, leading to potential data amplification attacks and improper validation of input arguments. This could allow an attacker to exploit the vulnerability to disrupt services or execute arbitrary code. Organizations using affected versions should prioritize upgrading to 0.25.0 to mitigate these risks.

CVE
CVE-2026-94636
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache

Original NVD Description

Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.