Impact
This vulnerability occurs when Apache Thrift reads framed transport or binary protocol data using a length supplied by a remote peer without enforcing an upper bound. The implementation allocates a buffer of that declared size, enabling a malicious client to request an inflated length that triggers an out‑of‑memory condition or excessive CPU usage during allocation, causing an uncaught exception and a crash of the Thrift service. The failure results in a denial of service impacting all clients that rely on the affected service. The weakness involves improper length validation and excessive memory allocation, mapping to CWEs such as 1188, 130, 248, 407, and 789.
Affected Systems
The flaw is present in Apache Thrift versions earlier than 0.25.0 and affects all language bindings supplied by the Apache Software Foundation—Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP, and D. Any deployment using these older versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, signifying no known large‑scale exploitation campaigns yet. However, the flaw can be activated by any client that connects to the Thrift service, giving it a network‑based attack vector. The potential outcome is a remote denial of service, making it an urgent concern for exposed Thrift services.
OpenCVE Enrichment