PT-2026-36992 · Apache · Apache Thrift

Jens Geyer

·

Published

2026-05-05

·

Updated

2026-05-07

·

CVE-2026-43870

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.23.0
Description Apache Thrift contains multiple issues, including an origin validation error, improper limitation of a pathname to a restricted directory (Path Traversal), improper neutralization of CRLF sequences in HTTP headers (HTTP Request/Response Splitting), and uncontrolled resource consumption.
Recommendations Upgrade to version 0.23.0.

Fix

Origin Validation Error

Path traversal

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-THRIFT-2026-43870
CVE-2026-43870

Affected Products

Apache Thrift