This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-526f-jxpj-jmg2 | Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption |
Wed, 06 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* |
Wed, 06 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 May 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache thrift |
|
| Vendors & Products |
Apache
Apache thrift |
Tue, 05 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |
| Title | Apache Thrift: Node.js web_server.js multi-vulnerability | |
| Weaknesses | CWE-113 CWE-22 CWE-346 CWE-400 |
|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-06T13:32:31.943Z
Reserved: 2026-05-04T14:24:45.315Z
Link: CVE-2026-43870
Updated: 2026-05-05T08:49:35.528Z
Status : Analyzed
Published: 2026-05-05T09:16:04.340
Modified: 2026-05-06T18:05:04.997
Link: CVE-2026-43870
No data.
OpenCVE Enrichment
Updated: 2026-05-06T16:30:06Z
Github GHSA