Description
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises when the PHP bindings of Apache Thrift parse string and numeric values using the TJSONProtocol without imposing any size restrictions. The lack of bounds allows an attacker to send overly large or malformed JSON payloads that cause the server to allocate excessive memory or other resources, potentially exhausting system limits and rendering the application unavailable. The core weakness is excessive resource allocation, which can lead to service disruption rather than direct code execution or data exfiltration.

Affected Systems

All deployments of Apache Thrift released before version 0.25.0 that use the PHP bindings and parse JSON input are affected. This includes environments where Thrift’s PHP component is employed to expose RPC services or to consume JSON data from untrusted sources.

Risk and Exploitability

The CVSS base score of 8.2 classifies the issue as high severity. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation is not directly quantified. However, the failure to validate input size provides a straightforward remote attack path when the vulnerable PHP service is exposed to external clients, enabling an attacker to trigger a denial of service by exhausting server resources.

Generated by OpenCVE AI on October 2, 2026 at 14:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Apache Thrift 0.25.0 update or a later fix that enforces size limits on the TJSONProtocol readers.
  • Configure the PHP environment to reject excessively large JSON payloads before they reach the Thrift layer, such as setting custom input size limits or using a reverse proxy filter.
  • If an immediate update is not possible, modify your application to use a bounded JSON reader or wrap the TJSONProtocol parsing with a size check to ensure payloads do not exceed a safe limit.

Generated by OpenCVE AI on October 2, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:53:37.255Z

Reserved: 2026-09-21T23:07:13.058Z

Link: CVE-2026-94644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:38.507

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:30:24Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling