CVE-2026-83745
Received Received - Intake

Memory Allocation Exploit in Apache Thrift Node.js and D Bindings

Vulnerability report for CVE-2026-83745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift  nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves memory allocation with an excessive size value due to improper handling of length parameters in Apache Thrift's Node.js and D language bindings. The WebSocket server transports read the payload length from the frame header and allocate memory immediately without verifying if the data has arrived. A small 14-byte frame can trigger allocations of up to 513 MiB in Node.js or 2 GiB in D, allowing attackers to consume excessive memory by sending repeated frames.

Detection Guidance

This vulnerability involves memory allocation issues in Apache Thrift's WebSocket server transports. Detection requires checking for unusually large memory allocations or suspicious WebSocket frames. Monitor for processes consuming excessive memory unexpectedly. Inspect network traffic for WebSocket frames with abnormally large payload lengths (e.g., 513 MiB or 2 GiB). Use tools like Wireshark to analyze WebSocket frames or system monitoring tools to track memory usage spikes.

Impact Analysis

This vulnerability can lead to denial-of-service (DoS) attacks by exhausting server memory, causing crashes or degraded performance. Attackers can send specially crafted frames to consume large amounts of memory, potentially disrupting services relying on Apache Thrift for communication.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that exhaust server resources, leading to service disruptions. Excessive memory allocation may cause system instability, affecting availability of personal or sensitive data processing systems.

Mitigation Strategies

Upgrade Apache Thrift to version 0.25.0 or later to fix the memory allocation vulnerability in Node.js and D language bindings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart