CVE-2026-43870
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
05/05/2026
Last modified:
05/05/2026
Description
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;), Improper Neutralization of CRLF Sequences in HTTP Headers (&#39;HTTP Request/Response Splitting&#39;), Uncontrolled Resource Consumption vulnerability in Apache Thrift.<br />
<br />
This issue affects Apache Thrift: before 0.23.0.<br />
<br />
Users are recommended to upgrade to version 0.23.0, which fixes the issue.



