Description
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The flaw occurs in the Dart bindings for Apache Thrift and allows a crafted request to allocate memory based on an incorrect length value. This misallocation can lead to buffer overflows or massive heap usage, potentially causing a crash, denial of service, or, in the worst case, memory corruption that could be leveraged for code execution. The vulnerability is rooted in improper size validation, as noted by CWE‑130 and CWE‑789.

Affected Systems

Apache Thrift before version 0.25.0 is affected. The issue is present in all deployments of the Thrift Dart binding that have not applied the 0.25.0 release.

Risk and Exploitability

With a CVSS score of 8.7 the risk is high. Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the attack vector likely involves remote clients sending a malformed Thrift message to an exposed service. Attackers could trigger excessive memory allocation or a buffer overflow by sending a malicious name length, leading to denial of service or potential code execution if the overflow can be controlled.

Generated by OpenCVE AI on October 2, 2026 at 11:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Apache Thrift Dart binding to version 0.25.0 or later, which contains the proper size validation logic.
  • Implement input validation on the Thrift server to reject messages that request unusually large buffer sizes before allocating memory.
  • Restrict network exposure of Thrift services, ensuring that only trusted clients can reach them and that traffic is filtered through firewall rules that limit payload size.

Generated by OpenCVE AI on October 2, 2026 at 11:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length
Weaknesses CWE-130
CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:28:58.258Z

Reserved: 2026-09-21T22:10:35.929Z

Link: CVE-2026-94633

cve-icon Vulnrichment

Updated: 2026-10-02T11:28:52.201Z

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:38.247

Modified: 2026-10-02T12:17:22.927

Link: CVE-2026-94633

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-02T10:13:00Z

Links: CVE-2026-94633 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:12Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value