Impact
The issue arises from an uncaught exception in the PHP bindings of Apache Thrift. When a non‑transport exception occurs within the TSimpleServer class, the process calls exit, terminating the whole PHP worker. This flaw is documented as CWE‑248. The immediate effect is a forced termination of the service, which an attacker can exploit to disrupt availability by repeatedly triggering the fault with crafted client requests.
Affected Systems
The vulnerability is limited to the Apache Thrift project, specifically the PHP binding implementation. All releases prior to version 0.25.0 are affected. The patch that resolves the issue is included in Apache Thrift 0.25.0 and later releases.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity, and the lack of a KEV listing suggests no public exploitation so far. The EPSS score is not available, making exploitation potential uncertain; however, the impact is severe if an attacker can continuously trigger the error. The likely attack vector is through a malicious client that sends malformed requests or induces an unexpected exception, thereby causing the server process to exit. Systems running vulnerable versions should be considered at high risk for targeted denial‑of‑service attacks.
OpenCVE Enrichment