CVE-2026-86535 - Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely
CVE ID :CVE-2026-86535 Published : Oct. 2, 2026, 12:17 p.m. | 1 hour, 3 minutes ago Description :Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings...