CVE-2026-94645EPSS p34.7%

CVE-2026-94645CVE-2026-94645

Description

Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Scoring

EPSS0.43% probability of exploitation · percentile 34.7% · 2026-10-06T12:00:23Z
Last modified2026-10-05
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.