天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-83663 Apache Thrift Go 绑定不受控递归漏洞

影响攻击者可远程触发进程崩溃,导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Apache Thrift 的 Go 语言绑定中,TFramedTransport 与 THeaderTransport 在处理无有效载荷的帧时,会递归调用 Read 而非循环处理,导致递归深度不受限制。攻击者只需发送特制帧即可耗尽 Go 栈,触发无法被 recover() 捕获的 fatal error,使整个进程终止。该漏洞影响 0.25.0 之前的版本。

影响范围

Apache Thrift

Apache Thrift 0.25.0 之前的版本,具体受影响版本范围暂无更细化的公开信息。

漏洞详情

漏洞类型为不受控递归(CWE-674)。两个 Go 传输实现在读取缓冲帧时,若该帧不产生任何有效载荷字节,会直接再次调用 Read 读取下一帧,而不是使用循环,从而形成递归。攻击者在 TFramedTransport 中发送声明大小为 0 的 4 字节帧,或在 THeaderTransport 中发送填满帧的 18 字节头部块,即可不断触发递归,最终达到 Go 栈上限并抛出 fatal error。

利用条件与风险

利用前提是目标使用受影响的 Go 绑定并暴露 Thrift 服务端口,攻击者无需认证即可发送特制帧。实战中可造成服务进程整体崩溃,形成拒绝服务。

修复建议

官方建议升级至 Apache Thrift 0.25.0 版本以修复该问题。临时缓解措施暂无公开信息,可考虑限制 Thrift 服务端口的网络访问。

原始情报

Uncontrolled Recursion vulnerability in Apache Thrift go bindings.

Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.