Apache Software FoundationCVE-2026-94646
Apache Thrift: prototype pollution
High8.7CVE-2026-94646 · Published Oct 2, 2026
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Thrift Product | < 0.25.0 | 0.25.0 |
Details and references
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 2 | Apache Thrift: resource exhaustion | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: resource exhaustion | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: resource exhaustion | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: infinite loop | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: infinite loop | High8.2 | 0.25.0 |
| Oct 2 | Apache Thrift: integer overflow | Critical9.2 | 0.25.0 |