rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-94657

Apache Thrift JavaME bindings allow unlimited resource allocation, potentially causing denial of service. The flaw exists in all versions be

Overview

Apache Thrift JavaME bindings allow unlimited resource allocation, potentially causing denial of service. The flaw exists in all versions before 0.25.0 and can be fixed by upgrading.

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

Denial of Service due to uncontrolled memory or CPU consumption can crash or slow applications. Attackers may target services using Thrift JavaME bindings. Defenders should monitor resource usage and enforce limits.

Remediation

Upgrade to Apache Thrift 0.25.0 or later. If upgrade is not feasible, apply resource quotas or run the service in a sandboxed environment to limit memory and CPU. Enable runtime monitoring and alerting for abnormal consumption.

Risk context

High severity with CVSS v3 score 7.5 and CVSS v4 score 8.2 indicates significant risk. Immediate attention is recommended to prevent potential service disruption.

Affected products

  • Apache Thrift
  • Apache Thrift JavaME

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

denial-of-service resource-exhaustion apache-thrift java high-severity patch availability

← All CVEs