CVE-2026-94648 - Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE ID :CVE-2026-94648 Published : Oct. 2, 2026, 12:17 p.m. | 1 hour, 3 minutes ago Description :Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to...