Resource Initialization and Status Code Issue in Apache Thrift WebSocket Server
CVE-2026-92834

6.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-92834?

A vulnerability has been identified in the Apache Thrift C++ WebSocket server, characterized by the use of an uninitialized resource which may result in the return of incorrect status codes. This issue, affecting versions prior to 0.25.0, poses risks that could lead to unpredictable behavior in applications relying on this server. Users are strongly advised to update to version 0.25.0 or later to address these vulnerabilities and enhance the security of their deployments.

Affected Version(s)

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.