A vulnerability, which was classified as problematic, has been found in Apache Thrift up to 0.22.0. This issue affects the function skip of the file Node.js. Performing a manipulation results in uncontrolled recursion.

This vulnerability was named CVE-2026-41636. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.