{"id":"ECHO-3142-9ee0-cc4e","upstream":["CVE-2026-94651"],"severity":[],"modified":"2026-10-05T18:43:47.546Z","affected":[{"package":{"ecosystem":"Echo","name":"thrift"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.19.0-4"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-94651"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-94651"}],"withdrawn":"2026-10-05T18:43:47.546Z","summary":"Java-only: TSaslNonblockingServer orphans a connection on a pre-auth\nparse error. Built with --without-java; no Java binary package is\nproduced.\n"}