Impact
Apache Thrift NodeJS bindings contain an infinite loop that never exits when processing a JSON protocol message containing a specially crafted member name. This loop stalls the Node.js event loop permanently, causing the server to become unresponsive and denying service to legitimate clients. The flaw also permits prototype pollution via improper handling of object prototype attributes, which could lead to further configuration or code execution weaknesses if combined with additional vulnerabilities.
Affected Systems
All users of Apache Thrift NodeJS bindings prior to version 0.25.0 are affected. The vulnerability exists in all releases of the Apache Software Foundation Thrift NodeJS bindings that expose a Thrift TJSONProtocol server to external input.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS data is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending a crafted JSON message to a Thrift service, triggering the infinite loop. The required conditions are network connectivity to the Thrift endpoint and client privileges sufficient to send JSON data. No additional privileges or local access are required, making the vulnerability remotely exploitable and capable of causing a denial of service.
OpenCVE Enrichment