PT-2026-36992 · Apache · Apache Thrift
Jens Geyer
·
Published
2026-05-05
·
Updated
2026-05-07
·
CVE-2026-43870
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache Thrift versions prior to 0.23.0
Description
Apache Thrift contains multiple issues, including an origin validation error, improper limitation of a pathname to a restricted directory (Path Traversal), improper neutralization of CRLF sequences in HTTP headers (HTTP Request/Response Splitting), and uncontrolled resource consumption.
Recommendations
Upgrade to version 0.23.0.
Fix
Origin Validation Error
Path traversal
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Thrift