← Back to CVE List
CVE-2026-43868NVD
Vulnerability Summary
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
External References
- https://lists.apache.org/thread/zj76dtwnbbs1m7z3focf4wd51pqpsmn9
- https://access.redhat.com/errata/RHSA-2026:26586
- https://access.redhat.com/errata/RHSA-2026:42644
- https://access.redhat.com/security/cve/CVE-2026-43868
- https://bugzilla.redhat.com/show_bug.cgi?id=2466670
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43868.json