Apache Thrift C++ WS Server Uninitialized Resource & Wrong Status (0.24.9)
CVE-2026-92834 Published on October 2, 2026
Apache Thrift: C++ WebSocket server transport does not read a full request length
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Vulnerability Analysis
CVE-2026-92834 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Types
Use of Uninitialized Resource
The software uses or accesses a resource that has not been initialized. When a resource has not been properly initialized, the software may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the software.
Return of Wrong Status Code
A function or operation returns an incorrect return value or status code that does not indicate an error, but causes the product to modify its behavior based on the incorrect result. This can lead to unpredictable behavior. If the function is used to make security-critical decisions or provide security-critical information, then the wrong status code can cause the software to assume that an action is safe, even when it is not.
Products Associated with CVE-2026-92834
Want to know whenever a new CVE is published for Apache Thrift? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Thrift:- Before 0.25.0 is affected.