CVE-2026-66859
CVE-2026-66859 is a high-severity vulnerability with a CVSS 4.0 base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-457.
Key facts
- Severity: High (CVSS 4.0 base score 8.7)
- EPSS exploit prediction: 0% (35th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-457
- Published:
- Last modified:
Description
NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Frequently asked questions
- What is CVE-2026-66859?
- NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
- How severe is CVE-2026-66859?
- CVE-2026-66859 has a CVSS 4.0 base score of 8.7, rated high severity.
- Is CVE-2026-66859 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (35th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-66859?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-66859 published?
- CVE-2026-66859 was published on 2026-10-02.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/n9rogg2166hl9y4ycq5njpvnxndr8y5o
Other CWE-457 vulnerabilities
- CVE-2026-6748 — Critical (CVSS 9.8): Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR…
- CVE-2025-54874 — Critical (CVSS 9.8): OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may…
- CVE-2025-53644 — Critical (CVSS 9.8): OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on…
- CVE-2026-78935 — Critical (CVSS 9.6): Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to…
- CVE-2026-14405 — Critical (CVSS 9.6): Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code…
- CVE-2026-84639 — Critical (CVSS 9.1): Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability…