Description
Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Potential Denial of Service via Stack Exhaustion
Action: Immediate Patch
AI Analysis

Impact

An uncontrolled recursion flaw exists in the c_glib bindings of Apache Thrift, where generated struct readers lack a recursion-depth guard. This can cause native stack exhaustion when parsing deeply nested Thrift structures, potentially leading to a service crash and denial of service. The weakness is classified as CWE‑674 (Uncontrolled Recursion).

Affected Systems

The vulnerability affects all Apache Thrift releases prior to 0.25.0 that use the c_glib bindings. Any application, client, or server that links against these bindings is subject to the flaw. The affected vendor is the Apache Software Foundation, and the product is Apache Thrift.

Risk and Exploitability

The CVSS score of 8.2 reflects high severity. No EPSS score is provided, so the probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves sending specially crafted Thrift requests that trigger deep recursion during parsing. If the service is exposed over the network, an attacker could send such a request, causing native stack exhaustion, leading to a process crash and denial of service.

Generated by OpenCVE AI on October 2, 2026 at 14:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to 0.25.0 or later, which adds a recursion-depth guard to the c_glib struct readers.
  • If a patch cannot be applied immediately, restrict network access to Thrift service endpoints using firewalls or ACLs to limit the number of clients that can send requests.
  • As a temporary measure, implement input validation at the application layer to limit the depth or size of incoming Thrift structures and monitor system logs for stack overflow errors.

Generated by OpenCVE AI on October 2, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T16:12:08.924Z

Reserved: 2026-09-21T23:18:07.040Z

Link: CVE-2026-94650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:38.763

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-94650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:15:07Z

Weaknesses