
Apache Thrift CVE-2026-43868: Rust implementation vulnerable to CVE-2020-13949 https://www.openwall.com/lists/oss-security/2026/05/05/2 CVE-2026-43869: TSSLTransportFactory.java hostname verification https://www.openwall.com/lists/oss-security/2026/05/05/3 CVE-2026-43870: Node.js web_server.js multi-vulnerability https://www.openwall.com/lists/oss-security/2026/05/05/4
Post summary
The message discloses several new CVEs affecting Apache Thrift components with brief details and references to Openwall discussions. No PoC, exploit code, patch, or active exploitation is reported.




