Impact
The flaw in Apache Thrift’s Java TSaslNonblockingServer class causes the Computation.run method to orphan a connection when a pre‑authentication parsing error occurs, leaving the socket and associated resources open. This improper control of resource expiration (CWE‑755) and failure to release the resource (CWE‑772) lead to uncontrolled accumulation of open connections, exhausting system memory and file descriptors and resulting in a denial of service. The impact is confined to the Thrift service process, but all clients to that service may become unavailable as the server’s capacity is saturated.
Affected Systems
The issue affects Apache Thrift Java bindings in all releases prior to version 0.25.0 from the Apache Software Foundation. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. Though the EPSS score is not reported, the vulnerability is not listed in the CISA KEV catalog, so exploitation remains possible but its likelihood cannot be precisely quantified. It is inferred from the description that an attacker can trigger the flaw by sending malformed pre‑authentication requests over the network to the TSaslNonblockingServer interface. The conditions for exploitation are minimal: network access to the exposed Thrift endpoint, so remote exploitation is likely and could be achieved against publicly reachable services where traffic is not filtered or rate‑limited.
OpenCVE Enrichment