Impact
The vulnerability resides in the Lua bindings of Apache Thrift where the function THttpTransport:_parseHeaders applies a backtracking regular expression to each header line. This algorithmic pattern exhibits quadratic complexity, so for requests with many headers or with specially crafted values the parsing can consume excessive CPU resources. Consequently an attacker can trigger a Denial of Service by sending a request that forces the server to perform a large number of regex operations. The weakness corresponds to CWE‑1333 (Inconsistent Algorithmic Complexity) and CWE‑407 (Unbounded Resource Consumption).
Affected Systems
Apache Software Foundation’s Apache Thrift, specifically the Lua language bindings, are affected in all releases prior to version 0.25.0. Any system that deploys Thrift 0.x and uses Lua bindings to service HTTP requests is vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting a moderate to low exploitation probability at present. However, the attack vector is remote and requires control over the HTTP request headers, which is feasible for any client connecting to the server. If an attacker can supply numerous or large header strings, the quadratic processing time can exhaust CPU resources, leading to service degradation or interruption.
OpenCVE Enrichment