Resource Management Vulnerability in Apache Thrift Ruby Bindings
CVE-2026-94656

8.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-94656?

A resource management vulnerability exists in the ruby bindings of Apache Thrift that allows for unrestricted allocation of resources. This can lead to potential denial of service conditions. Users are strongly encouraged to upgrade to version 0.25.0 to mitigate this vulnerability and enhance their system's stability and security.

Affected Version(s)

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sylwester Lachiewicz
.