vulnerabilityCVE-2026-83745
CVE-2026-83745
A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action