<Vulnerability name="CVE-2026-55968">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-27T11:06:17</PublicDate>
    <Bugzilla id="2507437" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507437" xml:lang="en:us">
thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache Thrift Node.js bindings. This vulnerability, stemming from inefficient algorithmic complexity and the allocation of resources without proper limits or throttling, allows a remote attacker to cause a Denial of Service (DoS). By exploiting this, an attacker can consume excessive resources, making the service unavailable to legitimate users.
    </Details>
    <Statement xml:lang="en:us">
This is an Important denial of service vulnerability in Apache Thrift Node.js bindings, which could allow a remote attacker to exhaust system resources due to inefficient algorithmic complexity. This flaw primarily impacts Red Hat OpenShift Container Platform components that utilize the vulnerable Thrift Node.js bindings, potentially leading to service unavailability.
    </Statement>
    <PackageState impact="important" cpe="cpe:/a:redhat:confidential_compute_attestation:1">
        <ProductName>Confidential Compute Attestation</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-sandboxed-containers/osc-podvm-payload-rhel9</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>thrift</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>conmon-rs</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>kata-containers</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift_update_service:5">
        <ProductName>Red Hat OpenShift Update Service</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-update-service/openshift-update-service-rhel8</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-55968
https://nvd.nist.gov/vuln/detail/CVE-2026-55968
http://www.openwall.com/lists/oss-security/2026/07/24/39
https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
    </References>
</Vulnerability>