Vulnerability Details CVE-2026-45112
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 78.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-45112
-
cpe:2.3:a:apache:thrift:0.19.0
-
cpe:2.3:a:apache:thrift:0.20.0
-
cpe:2.3:a:apache:thrift:0.21.0
-
cpe:2.3:a:apache:thrift:0.22.0
-
cpe:2.3:a:apache:thrift:0.23.0