Impact
Apache Thrift’s Java TSaslNonblockingServer can fail to properly handle exceptional conditions, allocating resources without limits and leaving uncaught exceptions. This leads to thread death or server crashes, effectively denying service to legitimate users. The weakness stems from improper cleanup after errors and absence of quota controls, corresponding to CWE-248, CWE-755, and CWE-770.
Affected Systems
All versions of Apache Thrift released before 0.25.0, specifically the Java bindings that use TSaslNonblockingServer, are affected. Any deployment that relies on these components without upgrading is at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation rates are uncertain. The likely attack vector is a remote client that sends malformed data or triggers an error condition, causing the server to allocate memory or threads beyond limits, resulting in resource exhaustion. Without a patch, an attacker could force the server into a non‑responsive state, disrupting availability.
OpenCVE Enrichment