Description
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

Apache Thrift NodeJS bindings contain an infinite loop that never exits when processing a JSON protocol message containing a specially crafted member name. This loop stalls the Node.js event loop permanently, causing the server to become unresponsive and denying service to legitimate clients. The flaw also permits prototype pollution via improper handling of object prototype attributes, which could lead to further configuration or code execution weaknesses if combined with additional vulnerabilities.

Affected Systems

All users of Apache Thrift NodeJS bindings prior to version 0.25.0 are affected. The vulnerability exists in all releases of the Apache Software Foundation Thrift NodeJS bindings that expose a Thrift TJSONProtocol server to external input.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS data is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending a crafted JSON message to a Thrift service, triggering the infinite loop. The required conditions are network connectivity to the Thrift endpoint and client privileges sufficient to send JSON data. No additional privileges or local access are required, making the vulnerability remotely exploitable and capable of causing a denial of service.

Generated by OpenCVE AI on October 2, 2026 at 13:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift NodeJS bindings to version 0.25.0 or later, which resolves the infinite loop and prototype pollution issues.
  • Restrict access to the Thrift service to trusted clients or network segments, and apply input validation or rate limiting to malformed JSON requests before they reach the TJSONProtocol decoder.
  • Continuously monitor Node.js process CPU usage and event loop latency; if a blockage is detected, restart the server or temporarily suspend the service until remediation is complete.

Generated by OpenCVE AI on October 2, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely
Weaknesses CWE-1321
CWE-835
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:38:16.628Z

Reserved: 2026-09-07T21:54:34.055Z

Link: CVE-2026-86535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:21.960

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-86535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:49:50Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')