CVE-2026-94639 Apache Thrift Java 绑定异常处理不当漏洞
影响可能导致服务异常或资源耗尽,造成拒绝服务
AI 研判
Apache Thrift Java 绑定中存在异常条件处理不当、资源分配无限制以及未捕获异常的问题。该漏洞影响 0.25.0 之前的版本,攻击者可能借此触发服务异常或资源耗尽。官方建议升级至 0.25.0 版本以修复该问题。
影响范围
Apache Thrift
Apache Thrift 0.25.0 之前的版本(Java 绑定)。
漏洞详情
该漏洞属于异常条件处理不当、资源分配无限制或缺少节流、未捕获异常类问题。成因在于 Java 绑定在处理异常或资源分配时缺乏有效限制与捕获机制。攻击者可能通过构造特定请求触发未捕获异常或大量资源消耗,从而导致服务不可用。
利用条件与风险
利用前提条件及 CVSS 评分暂无公开信息;若可远程触发,可能造成拒绝服务,影响服务可用性。
修复建议
官方修复方案为升级至 Apache Thrift 0.25.0 版本;临时缓解措施暂无公开信息。
原始情报
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.