ZERO
Back
vulnerabilityCVE-2026-83745

CVE-2026-83745

A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action