CVE-2026-86536
Received Received - Intake

Prototype Pollution in Apache Thrift JavaScript Bindings

Vulnerability report for CVE-2026-86536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a prototype pollution vulnerability in Apache Thrift's JavaScript bindings. It allows attackers to modify object prototype attributes, potentially leading to unexpected behavior or code execution. The issue affects all versions before 0.25.0.

Detection Guidance

Detection involves checking for improperly controlled modification of object prototype attributes in Apache Thrift JS bindings. Review code for unsafe deserialization or merge operations. Use static analysis tools to scan for prototype pollution patterns in JavaScript files.

Impact Analysis

An attacker could exploit this to alter object prototypes, causing application logic errors, bypassing security controls, or executing malicious code in your JavaScript applications using vulnerable Thrift versions.

Compliance Impact

The vulnerability (prototype pollution in Apache Thrift JS bindings) could lead to unauthorized data modification or access, potentially violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. However, specific compliance impacts depend on system usage and data processed.

Mitigation Strategies

Upgrade Apache Thrift to version 0.25.0 or later. Re-generate all JavaScript bindings after upgrading. Remove any custom patches or workarounds that may interfere with the fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart