CVE-2026-94648: Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift dart bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift Dart bindings using TJsonProtocol or TJSONProtocol are affected if they are running a version before 0.25.0.
What must an attacker be able to do to exploit this?
The issue concerns unbounded string-related resource allocation in the Dart JSON protocol implementations. The provided information does not specify the required access path or attacker privileges.
What is the recommended remediation?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.