CVE-2026-93926
Received Received - Intake

Memory Leak in Apache Thrift THeaderTransport

Vulnerability report for CVE-2026-93926, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Apache Thrift's THeaderTransport not releasing memory or resources properly after they are no longer needed. This can lead to memory leaks or resource exhaustion in systems using affected versions of Apache Thrift.

Detection Guidance

This vulnerability is specific to Apache Thrift versions before 0.25.0. Detection involves checking the installed version of Apache Thrift on your system. Use commands like 'thrift --version' or inspect package managers (e.g., 'dpkg -l | grep thrift' for Debian-based systems, 'rpm -qa | grep thrift' for RPM-based systems).

If the version is below 0.25.0, the system is vulnerable. No additional commands are required for detection as this is a version-based issue.

Impact Analysis

The vulnerability can cause system performance degradation or crashes due to memory or resource leaks. This may lead to service disruptions or instability in applications relying on Apache Thrift, especially in long-running processes.

Compliance Impact

This vulnerability involves a memory leak in Apache Thrift, which could lead to resource exhaustion or denial of service. While not directly tied to data privacy, such resource issues may indirectly impact compliance by degrading system reliability or availability, potentially affecting services handling sensitive data under GDPR or HIPAA.

Mitigation Strategies

Upgrade Apache Thrift to version 0.25.0 or later immediately. This can be done via package managers (e.g., 'apt-get upgrade thrift' or 'yum update thrift') or by downloading the latest release from the official Apache Thrift website.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93926. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart