Impact
A flaw in Apache Thrift’s WebSocket server transports causes the server to allocate a payload buffer based on the length field extracted from the frame header, without verifying that the declared number of bytes has actually been received. An attacker can send a frame that advertises a very large payload—up to 513 MiB in Node.js or 2 GiB in the D transport. The server immediately commits this memory, potentially exhausting the process or host resources and crashing or blocking the service. Because the connection remains open after the allocation in the Node.js binding, the attacker can repeatedly trigger the allocation, exacerbating the impact. This flaw falls under CWE‑130 (Improper Handling of Length Parameter Inconsistency) and CWE‑789 (Out-of-bounds Integer).
Affected Systems
The vulnerability affects Apache Thrift releases prior to version 0.25.0, specifically the Node.js and D language bindings that implement the WebSocket server transport. Any installation of Thrift that exposes a WebSocket endpoint using these bindings is impacted, regardless of the underlying operating system or runtime environment.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, but the issue is not listed in CISA’s KEV catalog, suggesting no publicly known exploits at this time. The likely attack vector is remote, via a malicious WebSocket client that can reach the server, and authentication is not required. The unchecked allocation makes the flaw trivial to trigger, giving the attacker a reliable path to cause denial of service or potentially assist in a larger denial or resource‑exhaustion attack.
OpenCVE Enrichment