CVE-2026-66858 Apache Thrift 协议跳过例程栈溢出漏洞
影响攻击者可通过深度嵌套消息耗尽栈,导致拒绝服务
Apache Thrift 多个语言绑定中的协议 skip 例程未应用绑定的递归限制,攻击者可构造嵌套未知字段足够深的报文来耗尽调用栈。该问题影响 Apache Thrift 0.25.0 之前的版本,涉及 Python C++ 加速器、PHP 库及其 thrift_protocol 扩展,以及 Perl、Lua、Smalltalk 和 OCaml 库。
影响范围
Apache Thrift 0.25.0 之前的版本;具体受影响绑定为 Python C++ 加速器(纯 Python 协议不受影响)、PHP 库及其 thrift_protocol 扩展、Perl、Lua、Smalltalk 和 OCaml 库。
漏洞详情
该漏洞属于栈耗尽型拒绝服务。Thrift 在解析报文时,遇到未知字段会调用协议 skip 例程跳过该字段,但部分绑定的 skip 例程未检查绑定的递归深度限制,导致深度嵌套的未知字段会不断递归调用 skip,最终耗尽线程栈并可能使进程崩溃。攻击者只需向使用受影响绑定的 Thrift 服务发送特制报文即可触发。
利用条件与风险
利用前提是目标服务使用受影响的 Thrift 绑定并对外暴露可接收报文的接口,无需认证即可尝试触发;实战中可造成服务崩溃或不可用,属于拒绝服务风险。
修复建议
官方已在 Apache Thrift 0.25.0 中修复该问题,建议升级至 0.25.0 或更高版本;若无法立即升级,可考虑在服务入口限制报文嵌套深度或对异常报文进行过滤,但暂无公开的官方临时缓解方案。
The protocol skip routine in several Apache Thrift bindings did not apply the binding’s recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.