Inefficient Algorithmic Complexity Vulnerability in Apache Thrift PHP Bindings
CVE-2026-94653

8.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-94653?

An inefficiency in the algorithmic complexity of the Apache Thrift PHP bindings can lead to excessive resource consumption. This vulnerability affects all versions prior to 0.25.0, making it imperative for users to upgrade to ensure optimal performance and security. Not taking action could result in degraded service or potential exploitation due to the inefficient handling of inputs.

Affected Version(s)

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.