Impact
The vulnerability allows uncontrolled recursion during the deserialization of Thrift structs processed by the Erlang bindings, leading to unbounded memory allocation. This can exhaust heap space and cause the server process to crash or become unresponsive. The weakness is a classic uncontrolled resource consumption identified by CWE-674 and an uncontrolled recursive depth guard represented by CWE-770.
Affected Systems
Apache Thrift Erlang bindings prior to version 0.25.0 from the Apache Software Foundation
Risk and Exploitability
With a CVSS score of 8.2 the severity is high. The EPSS score is currently not available, and the issue is not listed in the CISA KEV catalog. Because the flaw occurs during struct reads, an attacker can trigger it by delivering a specially crafted serialized request over the network to any Thrift service using the affected Erlang bindings, thereby inducing a denial‑of‑service. No local privilege or additional prerequisites are required beyond the ability to communicate with the Thrift endpoint.
OpenCVE Enrichment