Description
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift 
nodejs and D lang bindings.

Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.




This issue affects Apache Thrift before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Patch
AI Analysis

Impact

A flaw in Apache Thrift’s WebSocket server transports causes the server to allocate a payload buffer based on the length field extracted from the frame header, without verifying that the declared number of bytes has actually been received. An attacker can send a frame that advertises a very large payload—up to 513 MiB in Node.js or 2 GiB in the D transport. The server immediately commits this memory, potentially exhausting the process or host resources and crashing or blocking the service. Because the connection remains open after the allocation in the Node.js binding, the attacker can repeatedly trigger the allocation, exacerbating the impact. This flaw falls under CWE‑130 (Improper Handling of Length Parameter Inconsistency) and CWE‑789 (Out-of-bounds Integer).

Affected Systems

The vulnerability affects Apache Thrift releases prior to version 0.25.0, specifically the Node.js and D language bindings that implement the WebSocket server transport. Any installation of Thrift that exposes a WebSocket endpoint using these bindings is impacted, regardless of the underlying operating system or runtime environment.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, but the issue is not listed in CISA’s KEV catalog, suggesting no publicly known exploits at this time. The likely attack vector is remote, via a malicious WebSocket client that can reach the server, and authentication is not required. The unchecked allocation makes the flaw trivial to trigger, giving the attacker a reliable path to cause denial of service or potentially assist in a larger denial or resource‑exhaustion attack.

Generated by OpenCVE AI on October 2, 2026 at 13:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later, which removes the unchecked buffer allocation.
  • If an upgrade cannot be performed immediately, limit inbound WebSocket traffic to trusted hosts using firewall rules or reverse‑proxy authentication to reduce the attack surface.
  • Configure system or application memory limits (e.g., cgroups or ulimit) for the Thrift process to contain potential memory over‑consumption and mitigate impact.

Generated by OpenCVE AI on October 2, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift  nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)
Weaknesses CWE-130
CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T12:16:15.128Z

Reserved: 2026-08-31T22:53:07.156Z

Link: CVE-2026-83745

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T13:17:58.927

Modified: 2026-10-02T13:17:58.927

Link: CVE-2026-83745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-789

    Memory Allocation with Excessive Size Value