Impact
Apache Thrift’s Erlang bindings include a flaw in the thrift_json_protocol that reads an entire incoming JSON message without imposing any size limit. As a result, the server allocates memory proportionally to the message size, enabling an attacker to trigger memory exhaustion, crash the process, or otherwise disrupt service availability. The underlying weakness is classified as CWE‑770: Allocation of Resources Without Limits or Throttling.
Affected Systems
The vulnerability affects all Apache Thrift releases prior to 0.25.0 that use the Erlang bindings and expose the thrift_json_protocol to external clients. Any deployment that accepts JSON payloads over Thrift is potentially impacted, including embedded or server applications that rely on these bindings.
Risk and Exploitability
The CVSS score is 8.2, indicating high severity. The EPSS score is not available, so the current probability of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, through a client that can connect to the Thrift service and send a maliciously large JSON payload. Attackers could cause the server to consume excessive memory or crash, leading to denial of service for legitimate users. No additional privileges or lateral movement are required; exploitation simply requires network access to the affected Thrift endpoint.
OpenCVE Enrichment