Executive brief
Apache Thrift is a framework used to enable different software applications to communicate with each other efficiently. A security flaw in the Rust programming language version of this tool allows an attacker to overwhelm a server by sending specially crafted requests that consume all available system resources. This can lead to a complete service outage, preventing legitimate users and business operations from accessing the affected applications.
Technical details
A vulnerability classified as CWE-770 (Allocation of Resources Without Limits or Throttling) exists in the Apache Thrift Rust bindings. The flaw allows a remote, unauthenticated attacker to trigger excessive resource consumption by sending malicious payloads that the library fails to properly limit or throttle during processing. This results in a denial-of-service (DoS) affecting the availability of the application. The issue is resolved in Apache Thrift version 0.24.0.
Affected products
- Apache Software Foundation Thrift < 0.24.0
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched: Fixed in version 0.24.0