Description
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability occurs when Apache Thrift reads framed transport or binary protocol data using a length supplied by a remote peer without enforcing an upper bound. The implementation allocates a buffer of that declared size, enabling a malicious client to request an inflated length that triggers an out‑of‑memory condition or excessive CPU usage during allocation, causing an uncaught exception and a crash of the Thrift service. The failure results in a denial of service impacting all clients that rely on the affected service. The weakness involves improper length validation and excessive memory allocation, mapping to CWEs such as 1188, 130, 248, 407, and 789.

Affected Systems

The flaw is present in Apache Thrift versions earlier than 0.25.0 and affects all language bindings supplied by the Apache Software Foundation—Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP, and D. Any deployment using these older versions is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 denotes high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, signifying no known large‑scale exploitation campaigns yet. However, the flaw can be activated by any client that connects to the Thrift service, giving it a network‑based attack vector. The potential outcome is a remote denial of service, making it an urgent concern for exposed Thrift services.

Generated by OpenCVE AI on October 2, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later
  • Apply any additional vendor security patches or advisories for your deployment
  • Restrict access to the Thrift service to trusted networks via firewall or VPN and monitor for uncaught exception logs or service restarts

Generated by OpenCVE AI on October 2, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language)
Weaknesses CWE-1188
CWE-130
CWE-248
CWE-407
CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:42:44.813Z

Reserved: 2026-09-03T22:20:40.267Z

Link: CVE-2026-85494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:36.010

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-85494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:30:11Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-248

    Uncaught Exception

  • CWE-407

    Inefficient Algorithmic Complexity

  • CWE-789

    Memory Allocation with Excessive Size Value