PatchSiren cyber security CVE debrief
CVE-2026-45112 Apache Software Foundation CVE debrief
CVE-2026-45112 is an Allocation of Resources Without Limits or Throttling vulnerability affecting Apache Thrift Java bindings from version 0.19.0 up to but not including 0.24.0. This issue has a CVSS score of 6.9 and is considered medium severity. Users are advised to upgrade to version 0.24.0 to address the issue. The vulnerability, classified as CWE-770, allows for an allocation of resources without limits or throttling in Apache Thrift Java bindings. Affected users should review and adjust resource allocation limits in Apache Thrift Java bindings and monitor for potential exploitation attempts.
- Vendor
- Apache Software Foundation
- Product
- Apache Thrift
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of Apache Thrift Java bindings from version 0.19.0 up to but not including 0.24.0 should be aware of this vulnerability and take steps to mitigate it. Affected operator, platform, vulnerability-management, and security-team impact should be assessed. Users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Technical summary
The vulnerability, classified as CWE-770, allows for an allocation of resources without limits or throttling in Apache Thrift Java bindings. This issue has a CVSS score of 6.9 and is considered medium severity. The affected versions of Apache Thrift are from 0.19.0 up to but not including 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. The vulnerability affects Apache Thrift Java bindings, and users should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Defensive priority
Medium priority due to CVSS score of 6.9. Additional defensive measures should be considered, such as compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Upgrade to Apache Thrift version 0.24.0 or later
- Review and adjust resource allocation limits in Apache Thrift Java bindings
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from official sources indicates a vulnerability in Apache Thrift Java bindings. However, detailed information about potential exploits or affected systems is limited. The CVE record was published on 2026-07-27T12:16:44.560Z and has not been modified since then. The affected versions of Apache Thrift are from 0.19.0 up to but not including 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. Additional verification is required to confirm affected deployments and assess potential impact.
Official resources
-
CVE-2026-45112 CVE record
CVE.org
-
CVE-2026-45112 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
-
Source reference
af854a3a-2127-422b-91ae-364da2661108
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T12:16:44.560Z and has not been modified since then.