PT-2026-36992 · Apache · Apache Thrift

·

CVE-2026-43870

·

Published

2026-05-05

·

Updated

2026-05-07

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.23.0
Description Apache Thrift contains multiple issues, including an origin validation error, improper limitation of a pathname to a restricted directory (Path Traversal), improper neutralization of CRLF sequences in HTTP headers (HTTP Request/Response Splitting), and uncontrolled resource consumption.
Recommendations Upgrade to version 0.23.0.

Exploit

Fix

Resource Exhaustion

Path traversal

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-THRIFT-2026-43870
CVE-2026-43870
GHSA-526F-JXPJ-JMG2
RHSA-2026:53412
RHSA-2026:53413
RHSA-2026:53415

Affected Products

Apache Thrift