CVE-2026-90440

thrift: Uncaught Exception (CVE-2026-90440)

Description

Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamithrift

Metrics

8.2
Source: cna-v4
34.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-09 10:53 UTC
CWE-248, CWE-755, CWE-404

Weakness classes (CWE)

  • CWE-248Base

    Uncaught Exception

    An exception is thrown from a function, but it is not caught.

    cwe.mitre.org →
  • CWE-755Class

    Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

    cwe.mitre.org →
  • CWE-404Class

    Improper Resource Shutdown or Release

    The product does not release or incorrectly releases a resource before it is made available for re-use.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-02 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-90440","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-10-02 12:17 UTC· security@apache.org
    • Description: Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-404
    • CWE: CWE-248