{"id":"CVE-2026-94656","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-94656","generatedAt":"2026-10-02T15:52:22.863Z","title":"Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.","description":"Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","published":"2026-10-02T13:18:03.000Z","lastModified":"2026-10-02T14:30:28.000Z","status":"Deferred","sourceIdentifier":"security@apache.org","cvss":{"version":"4.0","score":8.2,"severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M"},"cwe":["CWE-770"],"affected":[],"epss":null,"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unscored. Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[{"kind":"new","label":"New CVE","at":"2026-10-02T13:18:03.000Z","detail":{"score":"8.2","severity":"HIGH","publishedAt":"2026-10-02T13:18:02.570Z"},"summary":"New CVE, high severity (CVSS 8.2)."}],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","source":"security@apache.org"},{"url":"https://lists.apache.org/thread/lg97w2yvg3c6z06l8m5xs3j3v2m6mvj8","source":"security@apache.org"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-94656","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}