CVE-2026-43868Disclosure(apache / thrift)

LOWCVSS 5.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch apache thrift systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789CWE-1285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thrift

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
thrift

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-05: 4Patch / Workaround · 2026-05-05: 2Technical Details · 2026-05-05: 305-05
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Thrift CVE-2026-43868: Rust implementation vulnerable to CVE-2020-13949 https://www.openwall.com/lists/oss-security/2026/05/05/2 CVE-2026-43869: TSSLTransportFactory.⁠java hostname verification https://www.openwall.com/lists/oss-security/2026/05/05/3 CVE-2026-43870: Node.js web_server.js multi-vulnerability https://www.openwall.com/lists/oss-security/2026/05/05/4

    Post summary

    The feed discloses several Apache Thrift CVEs, providing concise technical details about each, and referencing Openwall mailing list posts.

    02052471
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43868 CVE-2026-43868 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43868

    Post summary

    The text contains only a repeat of the CVE identifier and a link without further details.

    0000041
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43868 Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to ver… https://www.cve.org/CVERecord?id=CVE-2026-43868 ----- Traducción: CVE-2026-43868 Asi… http://infoflow.cloud`

    Post summary

    A new CVE (2026-43868) is announced for Apache Thrift versions before 0.23.0, with a memory‑allocation flaw. Users are advised to upgrade, but no PoC, exploit, or active exploitation details are provided.

    0000026
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-43868 Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to ver… https://www.cve.org/CVERecord?id=CVE-2026-43868

    Post summary

    The advisory announces CVE‑2026‑43868 affecting Apache Thrift before 0.23.0 and urges users to upgrade as a patch to mitigate the memory allocation vulnerability.

    00000135
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachethrift---

Explore more