Description
Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Uncontrolled recursion causing stack exhaustion and denial of service
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when the TProtocolUtil.skip function in Apache Thrift’s Dart and Java ME bindings follows peer‑chosen nesting to any depth the stack permits, which can lead to unbounded recursion and stack exhaustion. This flaw permits an attacker to trigger a crash or DoS condition by sending a request containing deeply nested protocol frames. The weakness is classified as unchecked recursion (CWE‑674).

Affected Systems

Any installation of Apache Thrift before version 0.25.0 that includes the Dart or Java ME bindings is affected. Users of these bindings should verify their Thrift version and upgrade if necessary, as only 0.25.0 and later contains the mitigation.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker who can send a specially crafted Thrift request that forces the server to recurse deeply; this inference is based on the nature of the bug. Exploitation would require network access to the Thrift service and the ability to craft nested protocol messages, potentially leading to a crash and service interruption.

Generated by OpenCVE AI on October 2, 2026 at 13:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch to upgrade to Apache Thrift 0.25.0 or later.
  • Restrict external access to the Thrift service by firewalling or network segmentation to limit exposure to untrusted clients.
  • Enable monitoring of stack depth or memory usage so that recursion‑related crashes can be detected and remediated quickly.

Generated by OpenCVE AI on October 2, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME)
Weaknesses CWE-248
CWE-674
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T16:13:53.000Z

Reserved: 2026-09-03T22:00:32.562Z

Link: CVE-2026-85493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:35.877

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-85493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:30:11Z

Weaknesses