CVE-2026-41636: Apache Thrift: Node.js skip() recursion
Published Apr 28, 2026
·Updated
Apache Thrift: Node.js skip() recursion
Other sources
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
— NVD
Affected Software
3 affected componentsFixes available
Remediation
Event History
Apr 28, 2026
CVE Published
via MITRE·09:22 AM
Data Sourced
via MITRE·09:22 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 30, 2026
Data Sourced
via Microsoft·08:11 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:11 AM
Affected Software
Updated
via Microsoft·08:11 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-41636?
CVE-2026-41636 is categorized as a medium severity vulnerability due to its potential for denial of service through uncontrolled recursion.
2
How do I fix CVE-2026-41636?
To fix CVE-2026-41636, users should upgrade to Apache Thrift version 0.23.0 or later.
3
What components are affected by CVE-2026-41636?
CVE-2026-41636 affects the Node.js bindings of Apache Thrift versions prior to 0.23.0.
4
What type of vulnerability is CVE-2026-41636?
CVE-2026-41636 is classified as an uncontrolled recursion vulnerability.
5
Can CVE-2026-41636 lead to other security issues?
Yes, CVE-2026-41636 can lead to denial of service conditions, impacting system availability.