CVE-2026-58389
Last modified
CVE-2026-58389 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue..
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Thrift | < 0.24.0 |
References
- http://www.openwall.com/lists/oss-security/2026/07/24/44Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-58389?
How severe is CVE-2026-58389?
How do I fix CVE-2026-58389?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58378Allwinner H616 TV Box TV98 has ADB enabled and exposed to th…8.8
- CVE-2026-58379A flaw was found in GIMP's Paint Shop Pro (PSP) file format …7.3
- CVE-2026-5838A vulnerability was determined in PHPGurukul News Portal Pro…4.7
- CVE-2026-58380A flaw was found in GIMP's PNM file format parser. When pars…7.8
- CVE-2026-58381A flaw was found in GIMP's PSP file format parser. A double-…6.1
- CVE-2026-58384A flaw was found in GIMP's PSD parser. An integer overflow i…7.8
- CVE-2026-5839A vulnerability was identified in PHPGurukul News Portal Pro…4.7
- CVE-2026-58399@acastellon/auth is an authentication control system for mic…8.7
- CVE-2026-5840A security flaw has been discovered in PHPGurukul News Porta…4.7
- CVE-2026-58402Hugo is a static site generator. From 0.60.0 until 0.163.3, …5.4
- CVE-2026-58403Hugo is a static site generator. From v0.123.0 through v0.16…6.5
- CVE-2026-58404Hugo is a static site generator. From v0.162.0 through v0.16…6.8
Are you affected by CVE-2026-58389?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
