Vulnerability Details CVE-2026-45112
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-45112
-
cpe:2.3:a:apache:thrift:0.19.0
-
cpe:2.3:a:apache:thrift:0.20.0
-
cpe:2.3:a:apache:thrift:0.21.0
-
cpe:2.3:a:apache:thrift:0.22.0
-
cpe:2.3:a:apache:thrift:0.23.0