CVE-2026-41636General(apache / thrift)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache thrift systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thrift

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
thrift

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-28: 2Patch / Workaround · 2026-04-28: 104-28
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2026-41636 Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version … https://www.cve.org/CVERecord?id=CVE-2026-41636

    Post summary

    The statement highlights a patch requirement for Apache Thrift Node.js bindings (pre‑0.23.0) and advises users to upgrade, with a link to the CVE record.

    00000111
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41636 CVE-2026-41636 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41636

    Post summary

    The entry merely repeats the CVE ID and includes a link to a generic vulnerability page, offering no additional details about the vulnerability or its status.

    0000054
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachethrift-node.js-

Explore more