CyberRota Analysis
AI-GeneratedSeveral Apache Thrift bindings, including the Python C++ accelerator, PHP library, and others, are vulnerable due to a failure to enforce the binding's recursion limit, potentially leading to stack exhaustion from deeply nested messages. This high-severity vulnerability can result in application crashes and service disruptions. Organizations using affected versions should prioritize upgrading to version 0.25.0 to mitigate these risks.
Original NVD Description
The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.