Description
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Apache Thrift’s Java TSaslNonblockingServer can fail to properly handle exceptional conditions, allocating resources without limits and leaving uncaught exceptions. This leads to thread death or server crashes, effectively denying service to legitimate users. The weakness stems from improper cleanup after errors and absence of quota controls, corresponding to CWE-248, CWE-755, and CWE-770.

Affected Systems

All versions of Apache Thrift released before 0.25.0, specifically the Java bindings that use TSaslNonblockingServer, are affected. Any deployment that relies on these components without upgrading is at risk.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation rates are uncertain. The likely attack vector is a remote client that sends malformed data or triggers an error condition, causing the server to allocate memory or threads beyond limits, resulting in resource exhaustion. Without a patch, an attacker could force the server into a non‑responsive state, disrupting availability.

Generated by OpenCVE AI on October 2, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later to apply the official fix.
  • If upgrading is delayed, disable or remove TSaslNonblockingServer from the server configuration and replace it with a safer alternative, or enforce strict caps on thread and memory usage in the server process.
  • Implement application‑level input validation to reject malformed requests that could trigger the unhandled exception, and configure the JVM to enforce maximum thread and memory limits to mitigate resource exhaustion.

Generated by OpenCVE AI on October 2, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
Weaknesses CWE-248
CWE-755
CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T09:33:52.165Z

Reserved: 2026-09-21T22:59:14.964Z

Link: CVE-2026-94639

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:09.783

Modified: 2026-10-02T10:17:09.783

Link: CVE-2026-94639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:00:13Z

Weaknesses
  • CWE-248

    Uncaught Exception

  • CWE-755

    Improper Handling of Exceptional Conditions

  • CWE-770

    Allocation of Resources Without Limits or Throttling