Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45112

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

A flaw was found in Apache Thrift Java bindings. This vulnerability, categorized as an Allocation of Resources Without Limits or Throttling, allows a remote attacker to cause a denial of service by exhausting system resources. The flaw occurs when the application fails to properly limit or throttle resource allocation, leading to potential system instability or unresponsiveness.

Отчет

This vulnerability is rated as Important. It affects Apache Thrift Java bindings, which could lead to a denial of service due to uncontrolled resource allocation. This impacts Red Hat OpenShift Container Platform and Community Projects where vulnerable versions of Apache Thrift are utilized, potentially allowing an attacker to exhaust system resources.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Red Hat build of Apache Camel 4 for Quarkus 3libthriftAffected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Affected
Red Hat Ceph Storage 9rhceph/alloy-rhel10Affected
Red Hat Connectivity Link 1rhcl-1/authorino-rhel9Affected
Red Hat Data Grid 8libthriftNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2507439thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation

EPSS

Процентиль: 78%
0.0194
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 дней назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
12 дней назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
debian
12 дней назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

CVSS3: 7.5
github
12 дней назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 78%
0.0194
Низкий

7.5 High

CVSS3