high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-94654
Apache Thrift Python bindings contain an infinite loop due to an unreachable exit condition, which can cause denial of service by exhausting
Overview
Apache Thrift Python bindings contain an infinite loop due to an unreachable exit condition, which can cause denial of service by exhausting CPU resources. It affects all installations using Thrift versions older than 0.25.0.
Description
Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The infinite loop can lead to denial of service by consuming CPU and memory, impacting availability. Attackers can trigger the loop via crafted Thrift requests, affecting any service that relies on the vulnerable bindings. Defenders should monitor for abnormal CPU spikes and ensure services are patched. The impact is primarily on availability, with potential indirect confidentiality or integrity effects if services become unresponsive.
Remediation
Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, isolate the vulnerable service behind a rate limiter or firewall to restrict request volume. Apply any vendor-provided hotfixes and verify the loop condition is removed. Restart services after patching.
Risk context
Severity is high with CVSS v3 score 7.5 and v4 score 8.2, indicating a significant risk of denial of service. No EPSS data available, so prioritize based on severity.
Affected products
- Apache Thrift
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —