What is CVE-2026-45112?
CVE-2026-45112 is an Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings, affecting versions from 0.19.0 to before 0.24.0. It allows unconstrained resource allocation, potentially leading to denial of service. Users are advised to upgrade to version 0.24.0 to fix the issue.
Azərbaycanca: CVE-2026-45112, Apache Thrift-in Java bağlamalarında limitsiz resurs ayrılması və ya tənzimləmə (throttling) zəifliyidir. Bu zəiflik Apache Thrift-in 0.19.0-dan 0.24.0-a qədər versiyalarına təsir edir. İstifadəçilərə problemi həll etmək üçün 0.24.0 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which programming language bindings of Apache Thrift does CVE-2026-45112 affect?
This vulnerability affects the Java bindings of Apache Thrift.
Which version is recommended to upgrade to in order to fix CVE-2026-45112?
Users are advised to upgrade to Apache Thrift version 0.24.0 to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.