VYPR
High severity7.5OSV Advisory· Published Jul 27, 2026· Updated Jul 27, 2026

CVE-2026-45112

CVE-2026-45112

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.

This issue affects Apache Thrift: from 0.19.0 before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

5

Patches

Vulnerability mechanics

References

3

News mentions

2