Resource Initialization and Status Code Issue in Apache Thrift WebSocket Server
CVE-2026-92834
6.3MEDIUM
What is CVE-2026-92834?
A vulnerability has been identified in the Apache Thrift C++ WebSocket server, characterized by the use of an uninitialized resource which may result in the return of incorrect status codes. This issue, affecting versions prior to 0.25.0, poses risks that could lead to unpredictable behavior in applications relying on this server. Users are strongly advised to update to version 0.25.0 or later to address these vulnerabilities and enhance the security of their deployments.
Affected Version(s)
Apache Thrift 0 < 0.25.0