high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-94655
Apache Thrift Lua bindings allow unlimited resource allocation due to inefficient algorithmic complexity, enabling denial‑of‑service attacks
Overview
Apache Thrift Lua bindings allow unlimited resource allocation due to inefficient algorithmic complexity, enabling denial‑of‑service attacks. The flaw affects all Thrift releases before 0.25.0 and can exhaust CPU or memory on a server. Upgrading to 0.25.0 or later mitigates the issue.
Description
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The vulnerability compromises availability by permitting attackers to trigger resource exhaustion, potentially causing service outages. Confidentiality and integrity remain unaffected. Systems running Thrift services, especially those exposed to untrusted clients, are at risk.
Remediation
Upgrade Apache Thrift to version 0.25.0 or newer. If an upgrade is not immediately possible, restrict the number of concurrent Thrift requests, enforce request size limits, and monitor CPU/memory usage for abnormal spikes. Apply any vendor‑issued patches as soon as they are released.
Risk context
Severity is high with CVSS v3 score 7.5 and CVSS v4 score 8.2. No EPSS data is available. The risk is significant for exposed Thrift services and warrants prompt attention.
Affected products
- Apache Thrift
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —