CVE-2026-94655 - Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic
CVE ID :CVE-2026-94655 Published : Oct. 2, 2026, 1:18 p.m. | 2 hours, 2 minutes ago Description :Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users...