Back to vendor advisories
Microsoft Security Response CenterCVE-2026-86536

Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript

Medium 1 CVE Published Oct 3, 2026 at 1:04 AM UTC

Summary

Mariner

Products covered

  • azl3 thrift 0.24.0-1 on Azure Linux 3.0

Remediation

Release Notes

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.