Origin Validation Error and Path Traversal in Apache Thrift
CVE-2026-43870

7.3HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 May 2026

What is CVE-2026-43870?

A vulnerability in Apache Thrift prior to version 0.23.0 enables origin validation errors, path traversal issues, improper handling of CRLF sequences in HTTP headers, and uncontrolled resource consumption. This can potentially allow attackers to manipulate resources or perform unauthorized actions, making it essential for users to promptly upgrade to version 0.23.0 to mitigate associated risks.

Affected Version(s)

Apache Thrift 0 < 0.23.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.