Impact
This vulnerability arises from the Apache Thrift Node.js bindings' TJSONProtocol, which treats the container size declared by a peer as an unbounded loop bound. The unchecked quantity is used to allocate memory or iterate without limits, allowing an attacker to trigger massive resource consumption. The result is application slowdown or crash, effectively denying service. This flaw is categorized under CWE-770 for unbounded allocation.
Affected Systems
Affected clients are applications that use the Apache Thrift library prior to version 0.25.0 on Node.js. The issue is present in the Thrift Node.js TJSONProtocol implementation and affects all deployments that depend on the default bindings in those versions.
Risk and Exploitability
The CVSS score of 8.2 classifies the issue as high severity, and the absence of EPSS data indicates unknown current exploitation likelihood but cannot be ruled out. The corrupt data can be sent over the network to a Thrift service; no local privileges are required. If an attacker can speak the Thrift wire format, they can craft a payload with an inflated container size, leading to large memory allocation and potential denial of service. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment