🔐 CVE Alert

CVE-2026-83745

UNKNOWN 0.0

Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift  nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CWE CWE-789 CWE-130
Vendor apache software foundation
Product apache thrift
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache thrift

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache thrift are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Thrift
0 < 0.25.0
Apache Software Foundation / Apache Thrift
0 < 0.25.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1 lists.apache.org: https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc

Credits

Ho1aAs <[email protected]> for Node.js Apache Thrift Developers for D language