Infinite loopthrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Infinite loop in TCompactProtocol varint decoding, which reads continuation bytes without enforcing a maximum byte count. An attacker can hang the process deserializing a message by sending a TCompactProtocol varint whose continuation bit stays set across an unbounded run of bytes. This requires the application to deserialize attacker-controlled TCompactProtocol input.
How to fix Infinite loop? Upgrade thrift to version 0.24.0 or higher.
| |
Improper Certificate Validationthrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Improper Certificate Validation in the certificate validation process. An attacker can access sensitive information by performing a man-in-the-middle attack during network communication.
How to fix Improper Certificate Validation? Upgrade thrift to version 0.24.0 or higher.
| |
Improper Handling of Highly Compressed Data (Data Amplification)thrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the TZlibTransport read paths in the C++, Java, Python, and Go bindings. An attacker can exhaust memory or trigger a denial of service by sending a small zlib-compressed payload that expands beyond the transport’s intended message-size limits during decompression. The vulnerable code reads decompressed bytes without consistently counting them against the configured maximum message size, so repeated reads through TZlibTransport can keep accepting output from a highly compressed stream even after the limit should have been exceeded. This breaks applications that rely on Thrift’s message-size enforcement to cap untrusted input before it is fully decompressed.
Notes
- In the Java and Go bindings, the vulnerable path is the stream-oriented
read() behavior of TZlibTransport; applications that only write-through or otherwise avoid reading decompressed data are not exposed through this bug.
- The Python bindings expose an explicit decompressed-size limit parameter, and the default cap in Python tracks
HARD_MAX_FRAME_SIZE; deployments that override those constructors may see a different effective ceiling.
How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade thrift to version 0.24.0 or higher.
| |
Improper Handling of Highly Compressed Data (Data Amplification)thrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) through the ZLIB read path in thrift.transport.THeaderTransport.THeaderTransport. An attacker can force excessive memory and CPU use by sending a header-framed request with a small compressed payload that expands into a very large decompressed body. When THeaderTransport.readFrame() processes the THeaderTransformID.ZLIB transform, it unconditionally decompresses the payload with zlib.decompress(), so a compression bomb can amplify input into an oversized message and exhaust the Python process or service handling the request.
How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade thrift to version 0.24.0 or higher.
| |
Denial of Service (DoS)thrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Denial of Service (DoS). A server or client may run into an endless loop when fed with specific input data.
Note: This issue was found to be partially fixed within version 0.11.0. As such depending on the installed version it affects only certain language bindings.
How to fix Denial of Service (DoS)? Upgrade thrift to version 0.13.0 or higher.
| |
Authentication Bypassthrift is a Python bindings package for Apache Thrift.
Affected versions of this package are vulnerable to Authentication Bypass. It could bypass SASL negotiation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
How to fix Authentication Bypass? Upgrade thrift to version 0.10.0 or higher.
| |