CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server ceive transports
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Apache Thrift
CVE-2026-55968 is considered a high-severity vulnerability due to its potential to cause denial of service in affected systems.
To fix CVE-2026-55968, update your Apache Thrift installation to the latest version that addresses this vulnerability.
CVE-2026-55968 is a quadratic-time denial-of-service (DoS) vulnerability affecting Node.js server receive transports in Apache Thrift.
The affected software for CVE-2026-55968 is Apache Thrift, specifically in its Node.js implementation.
CVE-2026-55968 was published on July 24, 2026.