Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.23.0CPE matchmatch criteria | cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
May 5, 2026CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
May 4, 2026Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
May 2, 2026