Missing release of memory after effective lifetime, Missing release of resource after effective...

zetlyn/cve-ghsa vulnerability ghsa GHSA-qqwh-ph69-26jv cve CVE-2026-93926 known 2026-10-02

https://github.com/advisories/GHSA-qqwh-ph69-26jv

Properties

cweCWE-401
receipt
Source
GitHub advisories
Its words
CWE-401
Read by
field:cwes[].cwe_id
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-03 18:09 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-93926",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-401",
      "name": "Missing Release of Memory after Effective Lifetime"
    }
  ],
  "description": "Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.",
  "ghsa_id": "GHSA-qqwh-ph69-26jv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-qqwh-ph69-26jv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qqwh-ph69-26jv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-93926"
    }
  ],
  "nvd_published_at": "2026-10-02T11:17:37Z",
  "published_at": "2026-10-02T12:31:12Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-93926",
    "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
    "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb",
    "https://github.com/advisories/GHSA-qqwh-ph69-26jv"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Missing release of memory after effective lifetime, Missing release of resource after effective...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T12:31:19Z",
  "url": "https://api.github.com/advisories/GHSA-qqwh-ph69-26jv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-03 18:09 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-93926",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-401",
      "name": "Missing Release of Memory after Effective Lifetime"
    }
  ],
  "description": "Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.",
  "ghsa_id": "GHSA-qqwh-ph69-26jv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-qqwh-ph69-26jv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qqwh-ph69-26jv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-93926"
    }
  ],
  "nvd_published_at": "2026-10-02T11:17:37Z",
  "published_at": "2026-10-02T12:31:12Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-93926",
    "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
    "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb",
    "https://github.com/advisories/GHSA-qqwh-ph69-26jv"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Missing release of memory after effective lifetime, Missing release of resource after effective...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T12:31:19Z",
  "url": "https://api.github.com/advisories/GHSA-qqwh-ph69-26jv",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

Missing release of memory after effective lifetime, Missing release of resource after effective... Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.