Description
Uncaught exception vulnerability in Apache Thrift PHP bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The issue arises from an uncaught exception in the PHP bindings of Apache Thrift. When a non‑transport exception occurs within the TSimpleServer class, the process calls exit, terminating the whole PHP worker. This flaw is documented as CWE‑248. The immediate effect is a forced termination of the service, which an attacker can exploit to disrupt availability by repeatedly triggering the fault with crafted client requests.

Affected Systems

The vulnerability is limited to the Apache Thrift project, specifically the PHP binding implementation. All releases prior to version 0.25.0 are affected. The patch that resolves the issue is included in Apache Thrift 0.25.0 and later releases.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity, and the lack of a KEV listing suggests no public exploitation so far. The EPSS score is not available, making exploitation potential uncertain; however, the impact is severe if an attacker can continuously trigger the error. The likely attack vector is through a malicious client that sends malformed requests or induces an unexpected exception, thereby causing the server process to exit. Systems running vulnerable versions should be considered at high risk for targeted denial‑of‑service attacks.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift PHP bindings to version 0.25.0 or newer.
  • Deploy fail‑over or restart mechanisms to automatically bring the service back up if it crashes, reducing downtime during a DoS attempt.
  • Monitor server logs and uptime to detect sudden crashes and alert when the process terminates unexpectedly.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:15:00 +0000

Type Values Removed Values Added
Description Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:57:14.927Z

Reserved: 2026-09-21T23:05:15.789Z

Link: CVE-2026-94642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:38.377

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:30:11Z

Weaknesses