PatchSiren cyber security CVE debrief
CVE-2026-94651 Apache Software Foundation CVE debrief
Apache Thrift Java bindings have an improper handling of exceptional conditions vulnerability. This issue affects Apache Thrift before version 0.25.0 and can cause a connection to be orphaned on a pre-auth parse error. The vulnerability can lead to denial of service and potentially impact the availability of services relying on Apache Thrift. Defenders should assess exposure and prioritize upgrading to version 0.25.0 or later. The impact and exploitation of this vulnerability are not well established, and further verification is required.
- Vendor
- Apache Software Foundation
- Product
- Apache Thrift
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-02
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-02
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Apache Thrift deployments should assess exposure and prioritize upgrading to version 0.25.0 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who oversee the deployment and maintenance of Apache Thrift in their environments. The potential impact on service availability and the lack of detailed exploitation information necessitate a thorough review of affected systems and
Why it matters
Defenders should care about this vulnerability because it can cause connections to be orphaned on a pre-auth parse error, potentially leading to denial of service. Apache Thrift deployments should assess exposure and prioritize upgrading to version 0.25.0 or later. The impact and exploitation of this vulnerability are not well established, and further verification is required.
- Potential denial of service due to orphaned connections
- Need to verify and upgrade affected systems and dependencies
- Possible increased monitoring and logging requirements
Technical summary
The Apache Thrift Java bindings have an improper handling of exceptional conditions vulnerability, which can cause a connection to be orphaned on a pre-auth parse error. This issue affects Apache Thrift before version 0.25.0. The vulnerability can lead to denial of service and potentially impact the availability of services relying on Apache Thrift. Defenders should prioritize upgrading to version 0.25.0 or later to mitigate this vulnerability. The technical details of the vulnerability indicate a need for careful review of affected systems and potential compensating controls.
Defensive priority
Defenders should prioritize upgrading to version 0.25.0 or later to mitigate this vulnerability.
Recommended defensive actions
- Upgrade to Apache Thrift version 0.25.0 or later
- Review and update affected systems and dependencies
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploitation or impact. Defenders should verify affected systems, review vendor guidance, and monitor for potential exploitation attempts. The lack of detailed information on exploitation or impact requires a cautious approach to ensure thorough mitigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94651 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94651
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94651 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94651
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-aut
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94651.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/rflzpdvtk8yhpzg99wkf5yf277nn7267
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.