Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs when the Delphi bindings of Apache Thrift’s buffered transport do not subtract the size of incoming reads from the MaxMessageSize limit. A client can send data larger than the authorized threshold, causing the server to allocate more memory than intended without any throttling. This can lead to excessive memory consumption, process crashes or a denial of service. The weakness belongs to CWE‑770, allocation of resources without limits or throttling.

Affected Systems

Apache Thrift versions earlier than 0.25.0, specifically the Delphi bindings used in its buffered transport module, are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating medium to high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that public exploitation evidence is limited. However, the likely attack vector is remote, via any Thrift client that can send oversized messages. An attacker could exploit the flaw by sending large payloads over the network, leading to resource exhaustion on the server. The vulnerability is mitigated by upgrading firmware to 0.25.0 or newer, which enforces proper size checks.

Generated by OpenCVE AI on October 2, 2026 at 13:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later
  • Configure MaxMessageSize to a conservative value and enforce bounds on incoming data
  • Implement rate limiting or firewall rules to control the rate of incoming Thrift traffic

Generated by OpenCVE AI on October 2, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T12:32:46.166Z

Reserved: 2026-07-24T21:26:05.559Z

Link: CVE-2026-66331

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T13:17:53.190

Modified: 2026-10-02T13:17:53.190

Link: CVE-2026-66331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling