Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache Thrift: resource exhaustion

High8.7CVE-2026-91137 · Published Oct 2, 2026

Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Thrift
Product
< 0.25.00.25.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770, CWE-834, CWE-1284

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: integer overflow
Critical9.2Oct 2