Impact
Heap-based buffer overflow occurs in the Apache Thrift C++ THeaderTransport::transform() function when the ZLIB transform is enabled. The function copies compressed frames into a write buffer without verifying that the compressed data fits, causing an out‑of‑bounds write. The overflow can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or cause a crash. This flaw is a classic example of CWE‑122.
Affected Systems
Applications built with Apache Thrift versions earlier than 0.25.0 are affected. The vulnerability arises when the ZLIB transform is used for frames sent by a remote peer. Any deployment that accepts untrusted Thrift traffic and enables ZLIB processing on outgoing frames is at risk.
Risk and Exploitability
With a CVSS score of 9.2 the risk is high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the overflow by sending large, poorly compressing frames over a network connection that the Thrift service accepts. The attack vector is remote and does not require authentication, as any client can supply frames that carry the malicious payload.
OpenCVE Enrichment