CVE-2026-94635: Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name
Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Lua bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift Lua bindings in versions before 0.25.0 are affected. The issue is specifically in TBinaryProtocol:readMessageBegin.
What does an attacker need to exploit this issue?
The supplied CVSS vector indicates network attack access, low attack complexity, and no required privileges or user interaction. The vulnerability involves improper handling of an inconsistent length parameter and resource allocation without limits or throttling.
What is the impact of successful exploitation?
The CVSS vector indicates an availability impact, with no indicated impact to confidentiality or integrity. Exploitation can cause uncontrolled resource allocation.
How should this be remediated?
Upgrade Apache Thrift to version 0.25.0. This version fixes the issue.