OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-94651

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable due to improper handling of exceptional conditions, leading to a resource release issue that could be exploited. This vulnerability has a high severity rating (CVSS 8.2) and could potentially allow attackers to exhaust system resources, impacting application availability. Organizations utilizing Apache Thrift in their Java applications should prioritize upgrading to version 0.25.0 to mitigate this risk.

CVE
CVE-2026-94651
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache Java

Original NVD Description

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.