high · CVSS v3 7.5 · CVSS v4 8.7
CVE-2026-94658
Apache Thrift Lua bindings contain an inefficient algorithmic complexity flaw that can lead to excessive resource consumption. The vulnerabi
Overview
Apache Thrift Lua bindings contain an inefficient algorithmic complexity flaw that can lead to excessive resource consumption. The vulnerability exists in all Thrift releases prior to 0.25.0. Upgrading to 0.25.0 or later mitigates the issue.
Description
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The flaw can cause denial of service by exhausting CPU or memory resources, compromising availability. Attackers may target services using Lua bindings, affecting any organization running legacy Thrift servers. Defenders should monitor for abnormal CPU spikes and restrict access to Thrift endpoints.
Remediation
Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, disable or remove Lua bindings from the Thrift service and restrict external access to the affected endpoints.
Risk context
High severity (CVSS 7.5/8.7) indicates significant risk; however, no EPSS data is available. Defenders should treat this as a high-priority issue and act promptly.
Affected products
- Apache Thrift 0.24
- Apache Thrift 0.23
- Apache Thrift 0.22
- Apache Thrift 0.21
- Apache Thrift 0.20
- Apache Thrift 0.19
- Apache Thrift 0.18
- Apache Thrift 0.17
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- —