Back

MEDIUM

Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back

Published Oct 2, 2026

Description

Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Oct 2, 2026
Updated Oct 5, 2026
Reserved Sep 21, 2026

CISA Vulnrichment

Updated Oct 5, 2026

NVD

Status Deferred
Modified Oct 5, 2026

Red Hat

No data

ENISA EUVD

Assigner apache
Published Oct 2, 2026
Updated Oct 5, 2026

GitHub

No data