Impact
The vulnerability arises when the TProtocolUtil.skip function in Apache Thrift’s Dart and Java ME bindings follows peer‑chosen nesting to any depth the stack permits, which can lead to unbounded recursion and stack exhaustion. This flaw permits an attacker to trigger a crash or DoS condition by sending a request containing deeply nested protocol frames. The weakness is classified as unchecked recursion (CWE‑674).
Affected Systems
Any installation of Apache Thrift before version 0.25.0 that includes the Dart or Java ME bindings is affected. Users of these bindings should verify their Thrift version and upgrade if necessary, as only 0.25.0 and later contains the mitigation.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker who can send a specially crafted Thrift request that forces the server to recurse deeply; this inference is based on the nature of the bug. Exploitation would require network access to the Thrift service and the ability to craft nested protocol messages, potentially leading to a crash and service interruption.
OpenCVE Enrichment