Improper Parameter Handling in Apache Thrift by Apache
CVE-2026-85494
8.7HIGH
What is CVE-2026-85494?
The vulnerability in Apache Thrift arises from improper handling of length parameters, leading to potential inconsistencies, uncaught exceptions, and inefficient algorithmic complexity. This flaw also includes issues related to memory allocation where excessively large size values may be used, and the initialization of resources with insecure defaults occurs across various programming languages, including Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP, and D. Users are strongly encouraged to update to version 0.25.0 to mitigate these vulnerabilities.
Affected Version(s)
Apache Thrift 0 < 0.25.0
Apache Thrift 0 < 0.25.0
Apache Thrift 0 < 0.25.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ho1aAs <xxy010605@gmail.com> for py, rb, erl, lua, dart, javame, d bindings
Perl/PHP bindings were found by the Apache Thrift project's own cross-language sweep
The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift.