high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-96286
Apache Thrift Perl bindings contain an uncaught exception that can lead to denial of service. The flaw exists in all releases before 0.25.0
Overview
Apache Thrift Perl bindings contain an uncaught exception that can lead to denial of service. The flaw exists in all releases before 0.25.0 and can affect any application using Thrift for interprocess communication.
Description
Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
Confidentiality: no direct data exposure. Integrity: potential service disruption. Availability: denial of service via repeated exception. Impacted parties: developers and operators of services built on Apache Thrift, especially those using Perl bindings.
Remediation
Upgrade to Apache Thrift 0.25.0 or later. If upgrade is not immediately possible, isolate Thrift services behind a firewall, limit connections, and implement custom exception handling wrappers. Monitor logs for uncaught exception patterns and apply temporary rate limiting.
Risk context
High severity with CVSS v3 score of 7.5 and CVSS v4 score of 8.2 indicates significant risk. No EPSS data is available. Prompt patching is recommended to mitigate potential denial of service.
Affected products
- Apache Thrift
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —