Impact
An uncontrolled recursion flaw exists in the c_glib bindings of Apache Thrift, where generated struct readers lack a recursion-depth guard. This can cause native stack exhaustion when parsing deeply nested Thrift structures, potentially leading to a service crash and denial of service. The weakness is classified as CWE‑674 (Uncontrolled Recursion).
Affected Systems
The vulnerability affects all Apache Thrift releases prior to 0.25.0 that use the c_glib bindings. Any application, client, or server that links against these bindings is subject to the flaw. The affected vendor is the Apache Software Foundation, and the product is Apache Thrift.
Risk and Exploitability
The CVSS score of 8.2 reflects high severity. No EPSS score is provided, so the probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves sending specially crafted Thrift requests that trigger deep recursion during parsing. If the service is exposed over the network, an attacker could send such a request, causing native stack exhaustion, leading to a process crash and denial of service.
OpenCVE Enrichment