rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-94654

Apache Thrift Python bindings contain an infinite loop due to an unreachable exit condition, which can cause denial of service by exhausting

Overview

Apache Thrift Python bindings contain an infinite loop due to an unreachable exit condition, which can cause denial of service by exhausting CPU resources. It affects all installations using Thrift versions older than 0.25.0.

Description

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The infinite loop can lead to denial of service by consuming CPU and memory, impacting availability. Attackers can trigger the loop via crafted Thrift requests, affecting any service that relies on the vulnerable bindings. Defenders should monitor for abnormal CPU spikes and ensure services are patched. The impact is primarily on availability, with potential indirect confidentiality or integrity effects if services become unresponsive.

Remediation

Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, isolate the vulnerable service behind a rate limiter or firewall to restrict request volume. Apply any vendor-provided hotfixes and verify the loop condition is removed. Restart services after patching.

Risk context

Severity is high with CVSS v3 score 7.5 and v4 score 8.2, indicating a significant risk of denial of service. No EPSS data available, so prioritize based on severity.

Affected products

  • Apache Thrift

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

Denial of Service Apache Thrift Python Infinite Loop High Severity Availability Patch

← All CVEs