CVE-2026-94653
CVE-2026-94653 is a high-severity vulnerability with a CVSS 4.0 base score of 8.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-407.
Key facts
- Severity: High (CVSS 4.0 base score 8.2)
- EPSS exploit prediction: 0% (35th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-407
- Published:
- Last modified:
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Frequently asked questions
- What is CVE-2026-94653?
- Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
- How severe is CVE-2026-94653?
- CVE-2026-94653 has a CVSS 4.0 base score of 8.2, rated high severity.
- Is CVE-2026-94653 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (35th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-94653?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-94653 published?
- CVE-2026-94653 was published on 2026-10-02 and last updated on 2026-10-05.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/8zbv1y4wzr3nn5mzmdph7b0n6tm0lc4m
Other CWE-407 vulnerabilities
- CVE-2026-94658 — High (CVSS 8.7): Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift:…
- CVE-2026-103604 — High (CVSS 8.7): Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and…
- CVE-2026-49250 — High (CVSS 8.7): Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From…
- CVE-2026-83613 — High (CVSS 8.7): xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to…
- CVE-2026-54284 — High (CVSS 8.7): sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion…
- CVE-2026-65623 — High (CVSS 8.7): Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via…