Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55968

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

A flaw was found in Apache Thrift Node.js bindings. This vulnerability, stemming from inefficient algorithmic complexity and the allocation of resources without proper limits or throttling, allows a remote attacker to cause a Denial of Service (DoS). By exploiting this, an attacker can consume excessive resources, making the service unavailable to legitimate users.

Отчет

This is an Important denial of service vulnerability in Apache Thrift Node.js bindings, which could allow a remote attacker to exhaust system resources due to inefficient algorithmic complexity. This flaw primarily impacts Red Hat OpenShift Container Platform components that utilize the vulnerable Thrift Node.js bindings, potentially leading to service unavailability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3thriftNot affected
Red Hat OpenShift Container Platform 4conmon-rsNot affected
Red Hat OpenShift Container Platform 4kata-containersAffected
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Not affected
Red Hat Hardened Imagesthrift-main-0.24.0-0.1.hum1FixedRHSA-2026:4983703.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2507437thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation

EPSS

Процентиль: 48%
0.00607
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
около 2 месяцев назад

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

msrc
около 2 месяцев назад

Apache Thrift: Node.js quadratic-time DoS in server receive transports

CVSS3: 7.5
debian
около 2 месяцев назад

Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...

CVSS3: 7.5
github
около 2 месяцев назад

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 48%
0.00607
Низкий

7.5 High

CVSS3