Description
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw in Apache Thrift’s Java TSaslNonblockingServer class causes the Computation.run method to orphan a connection when a pre‑authentication parsing error occurs, leaving the socket and associated resources open. This improper control of resource expiration (CWE‑755) and failure to release the resource (CWE‑772) lead to uncontrolled accumulation of open connections, exhausting system memory and file descriptors and resulting in a denial of service. The impact is confined to the Thrift service process, but all clients to that service may become unavailable as the server’s capacity is saturated.

Affected Systems

The issue affects Apache Thrift Java bindings in all releases prior to version 0.25.0 from the Apache Software Foundation. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. Though the EPSS score is not reported, the vulnerability is not listed in the CISA KEV catalog, so exploitation remains possible but its likelihood cannot be precisely quantified. It is inferred from the description that an attacker can trigger the flaw by sending malformed pre‑authentication requests over the network to the TSaslNonblockingServer interface. The conditions for exploitation are minimal: network access to the exposed Thrift endpoint, so remote exploitation is likely and could be achieved against publicly reachable services where traffic is not filtered or rate‑limited.

Generated by OpenCVE AI on October 2, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to 0.25.0 or newer to apply the fix that correctly releases connections after a parse error.
  • If an immediate upgrade is not possible, restrict access to the TSaslNonblockingServer endpoint with firewall rules that limit source IPs or ports.
  • Monitor the count and duration of open connections, and configure resource limits or timeouts to detect and mitigate orphaned connections early.

Generated by OpenCVE AI on October 2, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error
Weaknesses CWE-755
CWE-772
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:48:38.084Z

Reserved: 2026-09-21T23:20:49.569Z

Link: CVE-2026-94651

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:38.890

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:30:12Z

Weaknesses
  • CWE-755

    Improper Handling of Exceptional Conditions

  • CWE-772

    Missing Release of Resource after Effective Lifetime