CVE-2026-94645: Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift nodejs bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Applications using the Apache Thrift Node.js bindings with TJSONProtocol are affected if they run a version earlier than 0.25.0 and process peer-supplied protocol data.
What does an attacker need to exploit this issue?
An attacker needs to provide protocol input that declares a container size. The peer-declared size can be used as an unbounded loop bound.
What should teams do to remediate the issue?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue. The provided information does not specify an alternative mitigation for environments that cannot yet upgrade.