high · CVSS v3 7.5 · CVSS v4 8.7
CVE-2026-96277
Apache Thrift Ruby bindings before 0.25.0 contain an uncaught exception that can lead to improper handling of exceptional conditions. The fl
Overview
Apache Thrift Ruby bindings before 0.25.0 contain an uncaught exception that can lead to improper handling of exceptional conditions. The flaw may allow attackers to disrupt services or gain information. It is relevant to any application using Thrift's Ruby interface.
Description
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The vulnerability can compromise confidentiality by leaking error details, affect integrity by allowing unintended code paths, and impact availability through crashes or denial of service. Developers and operators of services built with Thrift Ruby are directly affected.
Remediation
Upgrade Apache Thrift to version 0.25.0 or later. If an upgrade is not immediately possible, disable or remove the Ruby bindings from the deployment, or implement exception handling wrappers around Thrift calls to catch and log errors gracefully.
Risk context
The CVE is rated high with CVSS v3 of 7.5 and v4 of 8.7, indicating significant risk. No EPSS data is available, so the urgency is based on the severity score alone.
Affected products
- Apache Thrift Ruby
- Apache Thrift
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- —