BIT-thrift-2026-94646

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/thrift/BIT-thrift-2026-94646.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-thrift-2026-94646
Aliases
  • CVE-2026-94646
Published
2026-10-09T10:53:32Z
Modified
2026-10-09T12:00:13Z
Summary
Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)
Details

Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings.

This issue affects Apache Thrift: before 0.25.0.

Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:thrift:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / thrift

Package

Name
thrift
Purl
pkg:bitnami/thrift

Severity

  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.25.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/thrift/BIT-thrift-2026-94646.json"