CVE-2026-82458EPSS p34.6%

CVE-2026-82458CVE-2026-82458

Description

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Scoring

EPSS0.43% probability of exploitation · percentile 34.6% · 2026-10-05T12:00:23Z
Last modified2026-10-02
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.