CVE-2026-43870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), Improper Neutralization of CRLF Sequences in HTTP Headers (&amp;#39;HTTP Request/Response Splitting&amp;#39;), Uncontrolled Resource Consumption vulnerability in Apache Thrift.<br /> <br /> This issue affects Apache Thrift: before 0.23.0.<br /> <br /> Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Impact