天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-66858 Apache Thrift 协议跳过例程栈溢出漏洞

影响攻击者可通过深度嵌套消息耗尽栈,导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Apache Thrift 多个语言绑定中的协议 skip 例程未应用绑定的递归限制,攻击者可构造嵌套未知字段足够深的报文来耗尽调用栈。该问题影响 Apache Thrift 0.25.0 之前的版本,涉及 Python C++ 加速器、PHP 库及其 thrift_protocol 扩展,以及 Perl、Lua、Smalltalk 和 OCaml 库。

影响范围

Apache Thrift

Apache Thrift 0.25.0 之前的版本;具体受影响绑定为 Python C++ 加速器(纯 Python 协议不受影响)、PHP 库及其 thrift_protocol 扩展、Perl、Lua、Smalltalk 和 OCaml 库。

漏洞详情

该漏洞属于栈耗尽型拒绝服务。Thrift 在解析报文时,遇到未知字段会调用协议 skip 例程跳过该字段,但部分绑定的 skip 例程未检查绑定的递归深度限制,导致深度嵌套的未知字段会不断递归调用 skip,最终耗尽线程栈并可能使进程崩溃。攻击者只需向使用受影响绑定的 Thrift 服务发送特制报文即可触发。

利用条件与风险

利用前提是目标服务使用受影响的 Thrift 绑定并对外暴露可接收报文的接口,无需认证即可尝试触发;实战中可造成服务崩溃或不可用,属于拒绝服务风险。

修复建议

官方已在 Apache Thrift 0.25.0 中修复该问题,建议升级至 0.25.0 或更高版本;若无法立即升级,可考虑在服务入口限制报文嵌套深度或对异常报文进行过滤,但暂无公开的官方临时缓解方案。

原始情报

The protocol skip routine in several Apache Thrift bindings did not apply the binding’s recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.