CVE-2026-94639: Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Java bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift deployments using the Java bindings are affected if they run a version before 0.25.0. The issue is specifically associated with TSaslNonblockingServer.
Can this be exploited remotely without authentication?
The CVSS vector indicates network access, low attack complexity, no required privileges, and no user interaction. The stated availability impact is high.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.