Impact
The flaw occurs when the Delphi bindings of Apache Thrift’s buffered transport do not subtract the size of incoming reads from the MaxMessageSize limit. A client can send data larger than the authorized threshold, causing the server to allocate more memory than intended without any throttling. This can lead to excessive memory consumption, process crashes or a denial of service. The weakness belongs to CWE‑770, allocation of resources without limits or throttling.
Affected Systems
Apache Thrift versions earlier than 0.25.0, specifically the Delphi bindings used in its buffered transport module, are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating medium to high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that public exploitation evidence is limited. However, the likely attack vector is remote, via any Thrift client that can send oversized messages. An attacker could exploit the flaw by sending large payloads over the network, leading to resource exhaustion on the server. The vulnerability is mitigated by upgrading firmware to 0.25.0 or newer, which enforces proper size checks.
OpenCVE Enrichment