Impact
This vulnerability arises when the PHP bindings of Apache Thrift parse string and numeric values using the TJSONProtocol without imposing any size restrictions. The lack of bounds allows an attacker to send overly large or malformed JSON payloads that cause the server to allocate excessive memory or other resources, potentially exhausting system limits and rendering the application unavailable. The core weakness is excessive resource allocation, which can lead to service disruption rather than direct code execution or data exfiltration.
Affected Systems
All deployments of Apache Thrift released before version 0.25.0 that use the PHP bindings and parse JSON input are affected. This includes environments where Thrift’s PHP component is employed to expose RPC services or to consume JSON data from untrusted sources.
Risk and Exploitability
The CVSS base score of 8.2 classifies the issue as high severity. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation is not directly quantified. However, the failure to validate input size provides a straightforward remote attack path when the vulnerable PHP service is exposed to external clients, enabling an attacker to trigger a denial of service by exhausting server resources.
OpenCVE Enrichment