Impact
A flaw in the Apache Thrift C++ library causes the zlib stream in THeaderTransport::untransform() to remain allocated on error paths, resulting in an unreleased memory region. The missing release is a classic example of a bad allocator usage, classified as bad allocation and poor resource release. The leak can grow unbounded when errors trigger repeatedly, consuming available memory and potentially degrading application performance or causing crashes. The impact is limited to resource exhaustion rather than direct code execution.
Affected Systems
Any deployment of Apache Thrift whose C++ implementation is older than version 0.25.0 is affected. This includes all applications that import Thrift’s transit library, such as internal RPC frameworks or services that rely on the THeaderTransport layer to encode or decode messages.
Risk and Exploitability
The CVSS score of 8.7 rates the vulnerability as high severity. The EPSS score is not available, but the absence of a KEV listing suggests no widely documented exploitation. Nonetheless, the flaw can be triggered by any component that engages the faulty transport during anomalous traffic or malformed requests, so an attacker who can induce many errors could exhaust system memory and cause a denial of service. The attack vector is most commonly local or remote if the affected service is exposed, making this a high‑risk vulnerability for any environment that runs an exposed Thrift interface.
OpenCVE Enrichment