Impact
The flaw is a NULL pointer dereference and use of an uninitialized variable in the c_glib Thrift multiplexed processor. When the processor receives a message it cannot route, it crashes, interrupting the service. This vulnerability is cataloged as CWE‑457 and CWE‑476.
Affected Systems
Any deployment of Apache Thrift using the c_glib bindings that runs a version older than 0.25.0. The issue applies across all products from the Apache Software Foundation related to Thrift.
Risk and Exploitability
The CVSS score of 8.7 signals a high‑severity denial‑of‑service impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. Attackers can trigger the crash remotely by sending a message that the processor cannot route, causing the service to terminate and denying legitimate users access.
OpenCVE Enrichment