rootpwn

high · CVSS v3 7.5 · CVSS v4 8.2

CVE-2026-96287

Apache Thrift Perl bindings contain an inefficient algorithmic complexity vulnerability that can lead to resource exhaustion. The flaw exist

Overview

Apache Thrift Perl bindings contain an inefficient algorithmic complexity vulnerability that can lead to resource exhaustion. The flaw exists in all versions prior to 0.25.0 and can be triggered by crafted input. Upgrading to 0.25.0 or later mitigates the issue.

Description

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Impact

The vulnerability can cause denial of service by exhausting CPU or memory resources when processing malicious Thrift requests. Attackers could disrupt services, impacting availability. Confidentiality and integrity are not directly affected, but the denial of service can indirectly affect business continuity. Defenders should monitor for abnormal resource usage and apply the patch promptly.

Remediation

Upgrade Apache Thrift to version 0.25.0 or later. If upgrade is not immediately possible, restrict Thrift traffic to trusted networks, enforce rate limiting, and monitor CPU/memory usage. Apply any vendor-provided hotfixes or configuration changes that limit input size.

Risk context

High severity (CVSS 7.5 v3, 8.2 v4) indicates a significant risk. No EPSS data available, so prioritize based on severity and potential for resource exhaustion in production environments.

Affected products

  • Apache Thrift 0.24.x
  • Apache Thrift 0.23.x
  • Apache Thrift 0.22.x
  • Apache Thrift 0.21.x
  • Apache Thrift 0.20.x
  • Apache Thrift 0.19.x
  • Apache Thrift 0.18.x
  • Apache Thrift 0.17.x

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.5
CVSS v4
8.2
EPSS
—

Apache Thrift Denial of Service Algorithmic Complexity Perl High Severity Resource Exhaustion Patch

← All CVEs