rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-94655

Apache Thrift Lua bindings allow unlimited resource allocation due to inefficient algorithmic complexity, enabling denial‑of‑service attacks

Overview

Apache Thrift Lua bindings allow unlimited resource allocation due to inefficient algorithmic complexity, enabling denial‑of‑service attacks. The flaw affects all Thrift releases before 0.25.0 and can exhaust CPU or memory on a server. Upgrading to 0.25.0 or later mitigates the issue.

Description

Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The vulnerability compromises availability by permitting attackers to trigger resource exhaustion, potentially causing service outages. Confidentiality and integrity remain unaffected. Systems running Thrift services, especially those exposed to untrusted clients, are at risk.

Remediation

Upgrade Apache Thrift to version 0.25.0 or newer. If an upgrade is not immediately possible, restrict the number of concurrent Thrift requests, enforce request size limits, and monitor CPU/memory usage for abnormal spikes. Apply any vendor‑issued patches as soon as they are released.

Risk context

Severity is high with CVSS v3 score 7.5 and CVSS v4 score 8.2. No EPSS data is available. The risk is significant for exposed Thrift services and warrants prompt attention.

Affected products

  • Apache Thrift

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

thrift lua resource-exhaustion denial-of-service high-severity patch availability

← All CVEs