rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-94658

Apache Thrift Lua bindings contain an inefficient algorithmic complexity flaw that can lead to excessive resource consumption. The vulnerabi

Overview

Apache Thrift Lua bindings contain an inefficient algorithmic complexity flaw that can lead to excessive resource consumption. The vulnerability exists in all Thrift releases prior to 0.25.0. Upgrading to 0.25.0 or later mitigates the issue.

Description

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The flaw can cause denial of service by exhausting CPU or memory resources, compromising availability. Attackers may target services using Lua bindings, affecting any organization running legacy Thrift servers. Defenders should monitor for abnormal CPU spikes and restrict access to Thrift endpoints.

Remediation

Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, disable or remove Lua bindings from the Thrift service and restrict external access to the affected endpoints.

Risk context

High severity (CVSS 7.5/8.7) indicates significant risk; however, no EPSS data is available. Defenders should treat this as a high-priority issue and act promptly.

Affected products

  • Apache Thrift 0.24
  • Apache Thrift 0.23
  • Apache Thrift 0.22
  • Apache Thrift 0.21
  • Apache Thrift 0.20
  • Apache Thrift 0.19
  • Apache Thrift 0.18
  • Apache Thrift 0.17

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.5
CVSS v4
8.7
EPSS
—

Apache Thrift Lua Denial of Service Algorithmic Complexity High Severity Resource Exhaustion

← All CVEs