Description
Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service caused by unhandled exception on WebSocket upgrade
Action: Immediate Patch
AI Analysis

Impact

Apache Thrift NodeJS bindings contain a flaw where upgrading a WebSocket connection without an error listener can result in an uncaught exception. This improper handling of exceptional conditions allows the event loop to terminate or become unstable, potentially resulting in a denial of service or application crash. The weakness is identified as CWE-248 (Improper Logging of Error Condition) and CWE-755 (Access Control on Sensitive Resource).

Affected Systems

Versions of Apache Thrift NodeJS prior to 0.25.0 are affected. The vulnerability applies to the Apache Thrift project when used as a NodeJS web server component. No specific product name beyond the Apache Thrift library is listed; any deployment that incorporates the older NodeJS bindings is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates the flaw is of high severity. As the EPSS score is not available, the exact likelihood of exploitation is not quantified, but the vulnerability is not listed in CISA KEV, which suggests no widely reported active exploitation currently. The likely attack vector is a remote attacker able to initiate or influence a WebSocket connection upgrade in an environment where the NodeJS binding is employed without an error listener, allowing the unhandled exception to crash the event loop. All users of Apache Thrift NodeJS bindings before 0.25.0 should assume the maximum exploitability until proven otherwise.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Thrift NodeJS bindings to version 0.25.0 or later.
  • Ensure your application registers an error listener for WebSocket connections to catch and log exceptions.
  • If upgrading is not immediately possible, add a global uncaughtException handler or wrap upgrade logic in try/catch to prevent event loop termination.

Generated by OpenCVE AI on October 2, 2026 at 13:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection
Weaknesses CWE-248
CWE-755
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T16:11:02.440Z

Reserved: 2026-09-22T21:43:55.390Z

Link: CVE-2026-96294

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:24.433

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-96294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-248

    Uncaught Exception

  • CWE-755

    Improper Handling of Exceptional Conditions