rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-96277

Apache Thrift Ruby bindings before 0.25.0 contain an uncaught exception that can lead to improper handling of exceptional conditions. The fl

Overview

Apache Thrift Ruby bindings before 0.25.0 contain an uncaught exception that can lead to improper handling of exceptional conditions. The flaw may allow attackers to disrupt services or gain information. It is relevant to any application using Thrift's Ruby interface.

Description

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The vulnerability can compromise confidentiality by leaking error details, affect integrity by allowing unintended code paths, and impact availability through crashes or denial of service. Developers and operators of services built with Thrift Ruby are directly affected.

Remediation

Upgrade Apache Thrift to version 0.25.0 or later. If an upgrade is not immediately possible, disable or remove the Ruby bindings from the deployment, or implement exception handling wrappers around Thrift calls to catch and log errors gracefully.

Risk context

The CVE is rated high with CVSS v3 of 7.5 and v4 of 8.7, indicating significant risk. No EPSS data is available, so the urgency is based on the severity score alone.

Affected products

  • Apache Thrift Ruby
  • Apache Thrift

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
8.7
EPSS
—

Apache Thrift Ruby Uncaught Exception High Severity Patch CVE-2026-96277

← All CVEs