Junglewise Threat Intelligence

CVE-2026-58389: Apache Thrift resource exhaustion in Rust bindings

CVE-2026-58389 · Severity: info · CVSS 8.7 · Published 2026-07-27

Vendors: Apache Software Foundation.

Executive brief

Apache Thrift is a framework used to enable different software applications to communicate with each other efficiently. A security flaw in the Rust programming language version of this tool allows an attacker to overwhelm a server by sending specially crafted requests that consume all available system resources. This can lead to a complete service outage, preventing legitimate users and business operations from accessing the affected applications.

Technical details

A vulnerability classified as CWE-770 (Allocation of Resources Without Limits or Throttling) exists in the Apache Thrift Rust bindings. The flaw allows a remote, unauthenticated attacker to trigger excessive resource consumption by sending malicious payloads that the library fails to properly limit or throttle during processing. This results in a denial-of-service (DoS) affecting the availability of the application. The issue is resolved in Apache Thrift version 0.24.0.

Affected products

  • Apache Software Foundation Thrift < 0.24.0

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched: Fixed in version 0.24.0

References