Impact
A defect in the Python TJSONProtocol of Apache Thrift allows unlimited allocation of memory by accepting JSON strings longer than the intended limit, leading to uncontrolled consumption of system resources. This constitutes a resource exhaustion weakness, potentially causing the Thrift service to become unresponsive or crash. The vulnerability does not expose direct code execution or data privacy risks but results in significant denial‑of‑service capability. The likely attack vector is sending oversized JSON payloads over the affected protocol interface, and based on the description it is inferred that this can be performed without authentication or prior compromise.
Affected Systems
Apache Thrift versions earlier than 0.25.0, all builds that include the Python bindings for TJSONProtocol. Users running these versions on any platform that exposes a Thrift service are affected.
Risk and Exploitability
The CVSS base score of 8.2 indicates a high severity level. The EPSS score is not available, so the exact likelihood of exploitation remains uncertain, but the flaw is well understood and could be targeted by adversaries seeking to overwhelm a service. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been documented. Attackers can trigger the flaw simply by sending large JSON requests to a publicly exposed Thrift service, with no requirement for privileged access.
OpenCVE Enrichment