high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-94657
Apache Thrift JavaME bindings allow unlimited resource allocation, potentially causing denial of service. The flaw exists in all versions be
Overview
Apache Thrift JavaME bindings allow unlimited resource allocation, potentially causing denial of service. The flaw exists in all versions before 0.25.0 and can be fixed by upgrading.
Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
Denial of Service due to uncontrolled memory or CPU consumption can crash or slow applications. Attackers may target services using Thrift JavaME bindings. Defenders should monitor resource usage and enforce limits.
Remediation
Upgrade to Apache Thrift 0.25.0 or later. If upgrade is not feasible, apply resource quotas or run the service in a sandboxed environment to limit memory and CPU. Enable runtime monitoring and alerting for abnormal consumption.
Risk context
High severity with CVSS v3 score 7.5 and CVSS v4 score 8.2 indicates significant risk. Immediate attention is recommended to prevent potential service disruption.
Affected products
- Apache Thrift
- Apache Thrift JavaME
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —