high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-96287
Apache Thrift Perl bindings contain an inefficient algorithmic complexity vulnerability that can lead to resource exhaustion. The flaw exist
Overview
Apache Thrift Perl bindings contain an inefficient algorithmic complexity vulnerability that can lead to resource exhaustion. The flaw exists in all versions prior to 0.25.0 and can be triggered by crafted input. Upgrading to 0.25.0 or later mitigates the issue.
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The vulnerability can cause denial of service by exhausting CPU or memory resources when processing malicious Thrift requests. Attackers could disrupt services, impacting availability. Confidentiality and integrity are not directly affected, but the denial of service can indirectly affect business continuity. Defenders should monitor for abnormal resource usage and apply the patch promptly.
Remediation
Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, restrict Thrift traffic to trusted networks, enforce rate limiting, and monitor CPU/memory usage. Apply any vendor-provided hotfixes or configuration changes that limit input size.
Risk context
High severity (CVSS 7.5 v3, 8.2 v4) indicates a significant risk. No EPSS data available, so prioritize based on severity and potential for resource exhaustion in production environments.
Affected products
- Apache Thrift 0.24.x
- Apache Thrift 0.23.x
- Apache Thrift 0.22.x
- Apache Thrift 0.21.x
- Apache Thrift 0.20.x
- Apache Thrift 0.19.x
- Apache Thrift 0.18.x
- Apache Thrift 0.17.x
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —