Description
Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch
AI Analysis

Impact

Apache Thrift’s Lua binding incorrectly processes the length parameter in the TBinaryProtocol readMessageBegin function, allowing an attacker to trigger uncontrolled memory allocations. This flaw does not directly compromise confidentiality or integrity but can lead to a denial of service by exhausting server resources. The vulnerability is rooted in improper handling of input length, as reflected by the associated CWE identifiers.

Affected Systems

This issue affects Apache Thrift implementations older than version 0.25.0. Clients or servers running any pre‑0.25.0 build are susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity risk. Although EPSS data is not available and the flaw is not listed in the CISA KEV catalog, the vulnerability could be exploited by an attacker who can send crafted Thrift messages to a target. The likely attack vector is remote, originating from the network layer where Thrift services are exposed. If the service is reachable from untrusted networks, the risk of a successful denial‑of‑service attack is significant.

Generated by OpenCVE AI on October 2, 2026 at 10:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later, which includes the fix for this flaw.
  • Restrict access to Thrift services by applying network‑level controls such as firewall rules or IP whitelisting to limit exposure to trusted parties.
  • Monitor server memory consumption and network traffic for anomalous spikes that may indicate an ongoing resource exhaustion attack.

Generated by OpenCVE AI on October 2, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name
Weaknesses CWE-130
CWE-770
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T09:07:56.691Z

Reserved: 2026-09-21T22:37:51.261Z

Link: CVE-2026-94635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:09.630

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94635

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-02T09:07:56Z

Links: CVE-2026-94635 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:23Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-770

    Allocation of Resources Without Limits or Throttling