Impact
Apache Thrift NodeJS bindings contain a flaw where upgrading a WebSocket connection without an error listener can result in an uncaught exception. This improper handling of exceptional conditions allows the event loop to terminate or become unstable, potentially resulting in a denial of service or application crash. The weakness is identified as CWE-248 (Improper Logging of Error Condition) and CWE-755 (Access Control on Sensitive Resource).
Affected Systems
Versions of Apache Thrift NodeJS prior to 0.25.0 are affected. The vulnerability applies to the Apache Thrift project when used as a NodeJS web server component. No specific product name beyond the Apache Thrift library is listed; any deployment that incorporates the older NodeJS bindings is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates the flaw is of high severity. As the EPSS score is not available, the exact likelihood of exploitation is not quantified, but the vulnerability is not listed in CISA KEV, which suggests no widely reported active exploitation currently. The likely attack vector is a remote attacker able to initiate or influence a WebSocket connection upgrade in an environment where the NodeJS binding is employed without an error listener, allowing the unhandled exception to crash the event loop. All users of Apache Thrift NodeJS bindings before 0.25.0 should assume the maximum exploitability until proven otherwise.
OpenCVE Enrichment