CVE-2026-94655: Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift deployments using the Lua bindings are affected if they run a version before 0.25.0. The issue is specifically in the Lua TJsonProtocol string and number readers.
What is the likely impact of exploitation?
Processing unbounded string or number input can cause excessive resource allocation and quadratic-time behavior. This can degrade availability through resource exhaustion or prolonged processing.
What should teams do to remediate the issue?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.