CVE-2026-86535: Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift NodeJS bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects Apache Thrift NodeJS bindings that use TJSONProtocol and are running a version before 0.25.0.
What is the impact of exploitation?
A crafted JSON member name can trigger an infinite loop that stalls the Node server's event loop indefinitely. The issue also involves improper control of object prototype attributes.
What remediation is available?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.