OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94648

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in Apache Thrift's Dart bindings allows for the allocation of resources without limits or throttling, potentially leading to denial-of-service conditions. Organizations using versions prior to 0.25.0 should prioritize upgrading to this version to mitigate the risk of resource exhaustion attacks. This is particularly critical for those relying on Apache Thrift in resource-sensitive environments.

CVE
CVE-2026-94648
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache

Original NVD Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.