CVE-2026-94646
Received Received - Intake

Prototype Pollution in Apache Thrift Node.js Bindings

Vulnerability report for CVE-2026-94646, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Apache Software Foundation

Description

Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache thrift to 0.25.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-248 An exception is thrown from a function, but it is not caught.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves three issues in Apache Thrift's Node.js bindings: an uncaught exception, improper validation of input quantity, and prototype pollution. Prototype pollution occurs when attackers modify object prototype attributes, potentially altering how the application behaves.

Detection Guidance

Detection involves checking for vulnerable versions of Apache Thrift nodejs bindings. Use commands like 'npm list thrift' or 'npm ls thrift' to check installed versions. Compare against version 0.25.0 or later.

Impact Analysis

An attacker could exploit this to execute arbitrary code, disrupt services, or access sensitive data. The high CVSS score (8.7) indicates significant risk, including potential data breaches or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR (data protection) and HIPAA (health data privacy). Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade Apache Thrift nodejs bindings to version 0.25.0 or later immediately. Use commands like 'npm update thrift' or reinstall with the latest version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94646. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart