rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-94656

Apache Thrift's Ruby bindings allow unlimited resource allocation, enabling attackers to exhaust server resources. The flaw exists in all ve

Overview

Apache Thrift's Ruby bindings allow unlimited resource allocation, enabling attackers to exhaust server resources. The flaw exists in all versions prior to 0.25.0. It can lead to denial‑of‑service conditions on services using Thrift.

Description

Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The vulnerability compromises availability by allowing attackers to consume CPU and memory until the Thrift service becomes unresponsive. Confidentiality and integrity are not directly affected, but the resulting DoS can disrupt dependent applications. Systems exposing Thrift endpoints are the primary targets.

Remediation

Upgrade Apache Thrift to version 0.25.0 or later, which implements resource limits in the Ruby bindings. If an upgrade is not immediately possible, configure OS‑level resource limits (ulimit, cgroups) for the Thrift process and monitor memory/CPU usage. Apply any vendor patches and test the service under load.

Risk context

High severity with CVSS 7.5 (v3) and 8.2 (v4). No EPSS data is available. The issue warrants prompt attention to prevent potential denial‑of‑service attacks.

Affected products

  • Apache Thrift (ruby bindings)

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

Apache Thrift Ruby resource exhaustion DoS high severity patch

← All CVEs