Disclosure summary
Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Source-reported weakness categories
CWE-130, CWE-789
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Oct
Open original source · Updated Oct 05, 2026
Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D)
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | azl3 thrift 0.24.0-1 on Azure Linux 3.0 | (MSRC status code 3) |
Vendor remediation references
- Release Notes · product IDs 0-17084
- Vendor guidance · product IDs 0-17084
NIST National Vulnerability Database · NVD-CVE-2026-83745
Open original source · Updated Oct 02, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-02T09:17:58-04:00
MODIFIED 2026-10-02T14:17:05-04:00
INGESTED 2026-10-06T11:45:30-04:00