PT-2026-36992 · Apache · Apache Thrift
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache Thrift versions prior to 0.23.0
Description
Apache Thrift contains multiple issues, including an origin validation error, improper limitation of a pathname to a restricted directory (Path Traversal), improper neutralization of CRLF sequences in HTTP headers (HTTP Request/Response Splitting), and uncontrolled resource consumption.
Recommendations
Upgrade to version 0.23.0.
Exploit
Fix
Resource Exhaustion
Path traversal
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Thrift