Description
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from the Apache Thrift Node.js bindings' TJSONProtocol, which treats the container size declared by a peer as an unbounded loop bound. The unchecked quantity is used to allocate memory or iterate without limits, allowing an attacker to trigger massive resource consumption. The result is application slowdown or crash, effectively denying service. This flaw is categorized under CWE-770 for unbounded allocation.

Affected Systems

Affected clients are applications that use the Apache Thrift library prior to version 0.25.0 on Node.js. The issue is present in the Thrift Node.js TJSONProtocol implementation and affects all deployments that depend on the default bindings in those versions.

Risk and Exploitability

The CVSS score of 8.2 classifies the issue as high severity, and the absence of EPSS data indicates unknown current exploitation likelihood but cannot be ruled out. The corrupt data can be sent over the network to a Thrift service; no local privileges are required. If an attacker can speak the Thrift wire format, they can craft a payload with an inflated container size, leading to large memory allocation and potential denial of service. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on October 2, 2026 at 13:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Thrift version 0.25.0 or later to apply the vendor‑issued fix.
  • If an upgrade cannot be performed immediately, implement input‑size validation on the server side to ensure container lengths are bounded by reasonable limits, mitigating unbounded allocation.
  • Enable application or process resource limits (e.g., memory limits, CPU quotas) on the Thrift service to prevent a single request from exhausting system resources.

Generated by OpenCVE AI on October 2, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound
Weaknesses CWE-1284
CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:51:40.324Z

Reserved: 2026-09-21T23:09:52.357Z

Link: CVE-2026-94645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:38.633

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:00:18Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-770

    Allocation of Resources Without Limits or Throttling