Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r67j-r569-jrwp

Опубликовано: 28 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Пакеты

Наименование

thrift

npm
Затронутые версииВерсия исправления

< 0.23.0

0.23.0

EPSS

Процентиль: 38%
0.00469
Низкий

8.7 High

CVSS4

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 7.5
redhat
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 7.5
nvd
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

msrc
3 месяца назад

Apache Thrift: Node.js skip() recursion

CVSS3: 7.5
debian
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings ...

EPSS

Процентиль: 38%
0.00469
Низкий

8.7 High

CVSS4

Дефекты

CWE-674