CVE-2026-94646: Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Thrift Node.js bindings before version 0.25.0 are affected. The issue is specifically associated with the Node.js server.js behavior.
What does an attacker need to do to trigger the issue?
An attacker needs to cause a per-connection error in the affected Node.js server. The reported triggers include malformed quantity input and prototype-pollution-related object attribute manipulation.
What is the impact of a successful trigger?
A per-connection error can result in an uncaught exception that ends the Node.js process, causing a denial of service.
What should teams do if they are running an affected version?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue. The provided information does not identify an alternative mitigation for systems that cannot be upgraded immediately.