CVE-2026-94634: Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default
Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Python bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected by this issue?
Apache Thrift Python bindings versions before 0.25.0 are affected. The issue is specifically associated with the Python TJSONProtocol implementation.
Is the vulnerable behavior enabled by default?
Yes. The string length limit is off by default, resulting in resource allocation without limits or throttling.
What is the recommended remediation?
Upgrade Apache Thrift Python bindings to version 0.25.0, which fixes the issue.