Impact
The flaw occurs in the Dart bindings for Apache Thrift and allows a crafted request to allocate memory based on an incorrect length value. This misallocation can lead to buffer overflows or massive heap usage, potentially causing a crash, denial of service, or, in the worst case, memory corruption that could be leveraged for code execution. The vulnerability is rooted in improper size validation, as noted by CWE‑130 and CWE‑789.
Affected Systems
Apache Thrift before version 0.25.0 is affected. The issue is present in all deployments of the Thrift Dart binding that have not applied the 0.25.0 release.
Risk and Exploitability
With a CVSS score of 8.7 the risk is high. Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the attack vector likely involves remote clients sending a malformed Thrift message to an exposed service. Attackers could trigger excessive memory allocation or a buffer overflow by sending a malicious name length, leading to denial of service or potential code execution if the overflow can be controlled.
OpenCVE Enrichment