Memory Allocation Issue in Apache Thrift’s WebSocket Server for Node.js and D Language Bindings
CVE-2026-83745
What is CVE-2026-83745?
The vulnerability in Apache Thrift’s Node.js and D language bindings arises from improper handling of the payload length in WebSocket server transports. When reading the payload length from the frame header, the server allocates memory based on the declared byte count without validating if the expected data has arrived. This allows for excessive memory consumption; for instance, a single ~14-byte frame can lead to a memory allocation of up to 513 MiB in the Node.js server and 2 GiB in the D transport. Furthermore, in the Node.js implementation, the connection remains open, permitting repeated exploitation by resending the frame. Users are strongly advised to upgrade to version 0.25.0 to mitigate this vulnerability.
Affected Version(s)
Apache Thrift 0 < 0.25.0
Apache Thrift 0 < 0.25.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved