vulnerabilityCVE-2026-66837
CVE-2026-66837
A flaw was found in Apache Thrift. An integer overflow within the PHP bindings leads to a stack-based buffer overflow when processing specially crafted data. A remote, unauthenticated attacker could exploit this flaw to crash the service, leading to a Denial of Service (DoS).
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action