Impact
Apache Thrift's Java TSaslNonblockingServer allocates memory for SASL frames without a limit before the client authenticates, creating a classic resource exhaustion vulnerability (CWE‑770). An attacker can send oversized frames to exhaust heap memory, resulting in the server crashing or becoming unresponsive.
Affected Systems
The flaw exists in all Apache Thrift releases prior to version 0.25.0. Upgrading to 0.25.0 or later removes the unbounded allocation logic and introduces safeguards against large frame sizes.
Risk and Exploitability
The vulnerability scores a CVSS of 8.7, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The lack of throttling suggests that an attacker could construct large frames from any remote client that can reach the Thrift service, but this is inferred from the description rather than explicitly stated. Without authentication enforced early, such traffic can be generated without user credentials, making exploitation likely if the service is exposed to untrusted networks.
OpenCVE Enrichment