Description
Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Upgrade
AI Analysis

Impact

A defect in the Python TJSONProtocol of Apache Thrift allows unlimited allocation of memory by accepting JSON strings longer than the intended limit, leading to uncontrolled consumption of system resources. This constitutes a resource exhaustion weakness, potentially causing the Thrift service to become unresponsive or crash. The vulnerability does not expose direct code execution or data privacy risks but results in significant denial‑of‑service capability. The likely attack vector is sending oversized JSON payloads over the affected protocol interface, and based on the description it is inferred that this can be performed without authentication or prior compromise.

Affected Systems

Apache Thrift versions earlier than 0.25.0, all builds that include the Python bindings for TJSONProtocol. Users running these versions on any platform that exposes a Thrift service are affected.

Risk and Exploitability

The CVSS base score of 8.2 indicates a high severity level. The EPSS score is not available, so the exact likelihood of exploitation remains uncertain, but the flaw is well understood and could be targeted by adversaries seeking to overwhelm a service. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been documented. Attackers can trigger the flaw simply by sending large JSON requests to a publicly exposed Thrift service, with no requirement for privileged access.

Generated by OpenCVE AI on October 2, 2026 at 11:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Apache Thrift library to version 0.25.0 or later where the string length limit has been correctly enforced.
  • If an immediate upgrade is not possible, consider configuring additional application‑level limits on the size of JSON input or implementing rate‑limiting to reduce the impact of large payloads.
  • Validate and restrict incoming JSON payload sizes in your application code, and monitor memory usage to detect potential exploitation attempts.

Generated by OpenCVE AI on October 2, 2026 at 11:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default
Weaknesses CWE-1188
CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:30:20.016Z

Reserved: 2026-09-21T22:17:58.691Z

Link: CVE-2026-94634

cve-icon Vulnrichment

Updated: 2026-10-02T11:30:12.287Z

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:09.467

Modified: 2026-10-02T12:17:23.057

Link: CVE-2026-94634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T11:45:07Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-770

    Allocation of Resources Without Limits or Throttling