Uncontrolled Recursion Vulnerability in Apache Thrift PHP Bindings by Apache
CVE-2026-96289
8.2HIGH
What is CVE-2026-96289?
An uncontrolled recursion vulnerability exists in the Apache Thrift PHP bindings, which can lead to excessive resource consumption and potential denial of service. Affected users are strongly advised to update to version 0.25.0 or later to mitigate this risk.
Affected Version(s)
Apache Thrift 0 < 0.25.0