Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Apache Thrift’s Erlang bindings include a flaw in the thrift_json_protocol that reads an entire incoming JSON message without imposing any size limit. As a result, the server allocates memory proportionally to the message size, enabling an attacker to trigger memory exhaustion, crash the process, or otherwise disrupt service availability. The underlying weakness is classified as CWE‑770: Allocation of Resources Without Limits or Throttling.

Affected Systems

The vulnerability affects all Apache Thrift releases prior to 0.25.0 that use the Erlang bindings and expose the thrift_json_protocol to external clients. Any deployment that accepts JSON payloads over Thrift is potentially impacted, including embedded or server applications that rely on these bindings.

Risk and Exploitability

The CVSS score is 8.2, indicating high severity. The EPSS score is not available, so the current probability of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, through a client that can connect to the Thrift service and send a maliciously large JSON payload. Attackers could cause the server to consume excessive memory or crash, leading to denial of service for legitimate users. No additional privileges or lateral movement are required; exploitation simply requires network access to the affected Thrift endpoint.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift to version 0.25.0 or later, which eliminates the unbounded read in the thrift_json_protocol.
  • If an upgrade cannot be performed immediately, enforce size limits on incoming JSON payloads at the application or network layer, such as by configuring a reverse proxy or firewall rule to reject requests exceeding a safe threshold.
  • Disable the thrift_json_protocol feature entirely if it is not required for your deployment, thereby removing the vulnerable code path.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:15:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:00:27.495Z

Reserved: 2026-09-23T20:45:40.800Z

Link: CVE-2026-96990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:39.180

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-96990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling