OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94639

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to an uncaught exception issue due to improper handling of exceptional conditions and unthrottled resource allocation. This vulnerability could lead to resource exhaustion and potential denial of service, making it critical for users of Apache Thrift in Java environments to prioritize upgrading to version 0.25.0 to mitigate the risk.

CVE
CVE-2026-94639
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache Java

Original NVD Description

improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.