Impact
Apache Thrift’s Lua binding incorrectly processes the length parameter in the TBinaryProtocol readMessageBegin function, allowing an attacker to trigger uncontrolled memory allocations. This flaw does not directly compromise confidentiality or integrity but can lead to a denial of service by exhausting server resources. The vulnerability is rooted in improper handling of input length, as reflected by the associated CWE identifiers.
Affected Systems
This issue affects Apache Thrift implementations older than version 0.25.0. Clients or servers running any pre‑0.25.0 build are susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk. Although EPSS data is not available and the flaw is not listed in the CISA KEV catalog, the vulnerability could be exploited by an attacker who can send crafted Thrift messages to a target. The likely attack vector is remote, originating from the network layer where Thrift services are exposed. If the service is reachable from untrusted networks, the risk of a successful denial‑of‑service attack is significant.
OpenCVE Enrichment