Memory Allocation Issue in Apache Thrift’s WebSocket Server for Node.js and D Language Bindings
CVE-2026-83745

8.7HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-83745?

The vulnerability in Apache Thrift’s Node.js and D language bindings arises from improper handling of the payload length in WebSocket server transports. When reading the payload length from the frame header, the server allocates memory based on the declared byte count without validating if the expected data has arrived. This allows for excessive memory consumption; for instance, a single ~14-byte frame can lead to a memory allocation of up to 513 MiB in the Node.js server and 2 GiB in the D transport. Furthermore, in the Node.js implementation, the connection remains open, permitting repeated exploitation by resending the frame. Users are strongly advised to upgrade to version 0.25.0 to mitigate this vulnerability.

Affected Version(s)

Apache Thrift 0 < 0.25.0

Apache Thrift 0 < 0.25.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ho1aAs <xxy010605@gmail.com> for Node.js
Apache Thrift Developers for D language
.