Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43870

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

A flaw was found in Apache Thrift. This vulnerability encompasses an origin validation error, improper limitation of a pathname to a restricted directory (path traversal), and improper neutralization of CRLF sequences in HTTP headers (HTTP request/response splitting). A remote attacker could exploit these issues to trigger uncontrolled resource consumption, leading to a Denial of Service (DoS) condition. Furthermore, path traversal could allow unauthorized access to files, and HTTP request/response splitting might enable other web-based attacks.

Отчет

This Important flaw in Apache Thrift allows a remote attacker to trigger a denial of service through uncontrolled resource consumption. Additionally, the vulnerability enables path traversal for unauthorized file access and HTTP request/response splitting, potentially leading to further web-based attacks in Red Hat products that integrate Apache Thrift.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Not affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel8Out of support scope
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-212Out of support scope
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-213Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat build of Apache Camel 4 for Quarkus 3libthriftNot affected
Red Hat Data Grid 8libthriftNot affected
Red Hat Enterprise Linux 10grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2466671apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities

EPSS

Процентиль: 32%
0.00394
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 7.3
nvd
3 месяца назад

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

msrc
3 месяца назад

Apache Thrift: Node.js web_server.js multi-vulnerability

CVSS3: 7.3
debian
3 месяца назад

Origin Validation Error, Improper Limitation of a Pathname to a Restri ...

CVSS3: 7.3
github
3 месяца назад

Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption

EPSS

Процентиль: 32%
0.00394
Низкий

8.6 High

CVSS3