thrift is vulnerable to Uncontrolled Recursion
53
Medium Risk
The c_glib protocol dispatch recurses while decoding nested Thrift structures without an effective bound tied to the incoming message. A crafted message with deeply nested fields drives that recursion until the native call stack is exhausted. Processing such input aborts the server handling the connection, causing a denial of service. The fix constrains nesting depth so untrusted payloads cannot recurse without bound.
You are affected if you are using a version that falls within the vulnerable range and you use the c_glib bindings to deserialize untrusted Thrift messages.
thrift is vulnerable to Uncontrolled Recursion in versions 0.0.1 - 0.23.0.
Upgrade the apache.thrift library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.