OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86535

HIGH · CVSS 8.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.25.0 are vulnerable to an infinite loop and prototype pollution due to improperly controlled modifications of object prototype attributes in the NodeJS bindings with TJSONProtocol. This can lead to denial-of-service conditions and potential manipulation of application behavior. Organizations using affected versions should prioritize upgrading to 0.25.0 to mitigate these risks.

CVE
CVE-2026-86535
Severity
HIGH
CVSS
8.7
EPSS
0.34%
Apache

Original NVD Description

Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.