rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-96286

Apache Thrift Perl bindings contain an uncaught exception that can lead to denial of service. The flaw exists in all releases before 0.25.0

Overview

Apache Thrift Perl bindings contain an uncaught exception that can lead to denial of service. The flaw exists in all releases before 0.25.0 and can affect any application using Thrift for interprocess communication.

Description

Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

Confidentiality: no direct data exposure. Integrity: potential service disruption. Availability: denial of service via repeated exception. Impacted parties: developers and operators of services built on Apache Thrift, especially those using Perl bindings.

Remediation

Upgrade to Apache Thrift 0.25.0 or later. If upgrade is not immediately possible, isolate Thrift services behind a firewall, limit connections, and implement custom exception handling wrappers. Monitor logs for uncaught exception patterns and apply temporary rate limiting.

Risk context

High severity with CVSS v3 score of 7.5 and CVSS v4 score of 8.2 indicates significant risk. No EPSS data is available. Prompt patching is recommended to mitigate potential denial of service.

Affected products

  • Apache Thrift

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

Apache Thrift Perl Denial of Service Uncaught Exception High Severity Patch Service Disruption

← All CVEs