CVE-2026-90440: Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service
Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Deployments using the D library's thrift.server.nonblocking.TNonblockingServer in Apache Thrift versions before 0.25.0 are affected. The issue concerns the non-blocking server implementation.
Does exploitation require authentication?
No. An unauthenticated remote attacker can trigger the condition and stop the affected non-blocking server.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.