CVE-2026-45112
published 2026-07-27CVE-2026-45112: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.07%
62.8th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | >= 0.19.0 < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | >= 0.19.0 < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| rhoai | odh-modelmesh-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-45112 [MEDIUM] CWE-770 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x denial of service
vuldb·2026-07-26
CVE-2026-45112 [LOW] Apache Thrift up to 0.23.x denial of service
A vulnerability labeled as problematic has been found in Apache Thrift up to 0.23.x. This affects an unknown part. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-45112. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
Red Hat
thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-45112 [HIGH] CWE-770 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
A flaw was found in Apache Thrift Java bindings. This vulnerability, categorized as an Allocation of Resources Without Limits or Throttling, allows a remote attacker to cause a denial of service by exhausting system resources. The flaw occurs when the application fails to properly limit or throttle resource allocation, leading to potential system instability or unresponsiveness.
Statement: This vulnerability is rated as Important. It affects Apache Thrift Java bindings, which could lead to a denial of service due to uncontrolled resource allocation. This impacts Red Hat OpenShift Container Platform and Community Projects where vulnerable versions of Apache Thrift are utilized, potentially allowing an attacke
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
bugzilla·2026-07-31·CVSS 7.5
CVE-2026-45112 [HIGH] CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-45112 python-avro: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
bugzilla·2026-07-31·CVSS 7.5
CVE-2026-45112 [HIGH] CVE-2026-45112 python-avro: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
CVE-2026-45112 python-avro: Apache Thrift: Denial of Service due to uncontrolled resource allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-45112 [HIGH] CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
CVE-2026-45112 thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published