high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-94656
Apache Thrift's Ruby bindings allow unlimited resource allocation, enabling attackers to exhaust server resources. The flaw exists in all ve
Overview
Apache Thrift's Ruby bindings allow unlimited resource allocation, enabling attackers to exhaust server resources. The flaw exists in all versions prior to 0.25.0. It can lead to denial‑of‑service conditions on services using Thrift.
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The vulnerability compromises availability by allowing attackers to consume CPU and memory until the Thrift service becomes unresponsive. Confidentiality and integrity are not directly affected, but the resulting DoS can disrupt dependent applications. Systems exposing Thrift endpoints are the primary targets.
Remediation
Upgrade Apache Thrift to version 0.25.0 or later, which implements resource limits in the Ruby bindings. If an upgrade is not immediately possible, configure OS‑level resource limits (ulimit, cgroups) for the Thrift process and monitor memory/CPU usage. Apply any vendor patches and test the service under load.
Risk context
High severity with CVSS 7.5 (v3) and 8.2 (v4). No EPSS data is available. The issue warrants prompt attention to prevent potential denial‑of‑service attacks.
Affected products
- Apache Thrift (ruby bindings)
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —