CVE-2026-43869Disclosure(apache / thrift)

LOWCVSS 7.3 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch apache thrift systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-297CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thrift

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
thrift

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-05-05: 5Patch / Workaround · 2026-05-05: 3Technical Details · 2026-05-05: 405-05
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets6 URLs
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Thrift CVE-2026-43868: Rust implementation vulnerable to CVE-2020-13949 https://www.openwall.com/lists/oss-security/2026/05/05/2 CVE-2026-43869: TSSLTransportFactory.⁠java hostname verification https://www.openwall.com/lists/oss-security/2026/05/05/3 CVE-2026-43870: Node.js web_server.js multi-vulnerability https://www.openwall.com/lists/oss-security/2026/05/05/4

    Post summary

    The message discloses several new CVEs affecting Apache Thrift components with brief details and references to Openwall discussions. No PoC, exploit code, patch, or active exploitation is reported.

    02052471
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Apache Thrift – CVE-2026-43869 Improper certificate validation flaw (host mismatch) in Apache Thrift. Affects versions before 0.23.0, allowing attackers to bypass TLS verification and potentially intercept traffic. Upgrade to v0.23.0+ immediately. #CVE #AppSec #Apache #Thrift #Security

    Post summary

    Apache Thrift CVE-2026-43869 is an improper certificate validation issue; users on versions before 0.23.0 are advised to update immediately.

    0002078
    121 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43869 CVE-2026-43869 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43869

    Post summary

    The post simply repeats the CVE ID and offers a link to a vulnerability page, without any additional context or actionable detail.

    0000038
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43869 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgr… https://www.cve.org/CVERecord?id=CVE-2026-43869 ----- Traducción: CVE-2026-43869 Val… http://infoflow.cloud`

    Post summary

    CVE-2026-43869 exposes improper certificate validation in Apache Thrift versions prior to 0.23.0, with an advisory recommending an upgrade.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-43869 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgr… https://www.cve.org/CVERecord?id=CVE-2026-43869

    Post summary

    The text announces the CVE, briefly explains its nature, and advises users to upgrade to a patched version.

    00000144
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachethrift---

Explore more