CVE-2026-94636
Received Received - Intake

Improper Data Handling in Apache Thrift Python Bindings

Vulnerability report for CVE-2026-94636, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-628 The product calls a function, procedure, or routine with arguments that are not correctly specified, leading to always-incorrect behavior and resultant weaknesses.
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache Thrift's Python bindings involves three issues: improper handling of highly compressed data leading to data amplification, function calls with incorrect arguments, and improper validation of input quantities. It affects versions before 0.25.0.

Detection Guidance

Detection involves checking the version of Apache Thrift py bindings. Run 'pip show thrift' or 'thrift --version' to verify if the installed version is before 0.25.0. If so, the system is vulnerable.

Impact Analysis

The vulnerability can lead to denial of service due to data amplification, unexpected behavior from incorrect function calls, and potential security bypasses from improper input validation. Attackers could exploit these to disrupt services or gain unauthorized access.

Compliance Impact

The vulnerability involves improper handling of compressed data and incorrect function arguments, which could lead to data amplification or processing errors. This may result in unauthorized data exposure or integrity issues, potentially violating GDPR principles of data minimization and security or HIPAA requirements for protected health information handling.

Mitigation Strategies

Upgrade Apache Thrift py bindings to version 0.25.0 or later. Use 'pip install --upgrade thrift' or the package manager for your system to apply the fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94636. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart