OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96289

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift PHP bindings are vulnerable to an uncontrolled recursion flaw, which could lead to denial of service conditions due to excessive resource consumption. Organizations utilizing affected versions prior to 0.25.0 should prioritize upgrading to the patched version to mitigate potential service disruptions.

CVE
CVE-2026-96289
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache

Original NVD Description

Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.