Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Immediate Patch
AI Analysis

Impact

Apache Thrift's Java TSaslNonblockingServer allocates memory for SASL frames without a limit before the client authenticates, creating a classic resource exhaustion vulnerability (CWE‑770). An attacker can send oversized frames to exhaust heap memory, resulting in the server crashing or becoming unresponsive.

Affected Systems

The flaw exists in all Apache Thrift releases prior to version 0.25.0. Upgrading to 0.25.0 or later removes the unbounded allocation logic and introduces safeguards against large frame sizes.

Risk and Exploitability

The vulnerability scores a CVSS of 8.7, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The lack of throttling suggests that an attacker could construct large frames from any remote client that can reach the Thrift service, but this is inferred from the description rather than explicitly stated. Without authentication enforced early, such traffic can be generated without user credentials, making exploitation likely if the service is exposed to untrusted networks.

Generated by OpenCVE AI on October 2, 2026 at 14:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the 0.25.0 or later Apache Thrift update, which limits frame allocation size.
  • Restrict access to the Thrift server by firewalling or placing it behind a VPN so that only trusted hosts can reach it.
  • Monitor server memory and CPU utilization and configure system limits or containers to isolate the Thrift process and prevent a single client from exhausting resources.

Generated by OpenCVE AI on October 2, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:07:29.248Z

Reserved: 2026-07-08T22:58:03.425Z

Link: CVE-2026-61373

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:20.847

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-61373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:15Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling