CVE WATCH / VULNERABILITY DETAIL
CVE-2026-86535
UNKNOWNCVSS 0NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.This issue affects Apache Thrift: before 0.25.0.Users are recommended to upgrade
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103622 HIGH 8.8
- CVE-2026-103625 HIGH 8.8
- CVE-2026-90970 CRITICAL 9.9
- CVE-2026-39600 MEDIUM 4.7
- CVE-2026-104638 MEDIUM 5.3
- CVE-2026-104625 MEDIUM 6.3
- CVE-2026-104637 HIGH 7.3
- CVE-2026-93875 HIGH 7.2
- CVE-2026-19652 CRITICAL 9.8
- CVE-2026-104613 MEDIUM 6.3