Prototype Pollution Vulnerability in Apache Thrift JS Bindings
CVE-2026-86536
6.3MEDIUM
What is CVE-2026-86536?
A vulnerability exists in Apache Thrift's JavaScript bindings that allows improperly controlled modification of object prototype attributes, commonly referred to as 'prototype pollution'. This flaw can lead to unintended behavior across applications that utilize these bindings, potentially resulting in data corruption or security breaches. Users are advised to upgrade to version 0.25.0 or later and regenerate their JavaScript code to remediate this issue effectively.
Affected Version(s)
Apache Thrift 0 < 0.25.0
Apache Thrift 0 < 0.25.0
Apache Thrift 0 < 0.25.0
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Thrift.