Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-43870PATCHED
apache · thrift

Apache Thrift: Node.js web_server.js multi-vulnerability

Description

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Affected Products

VendorProductVersions
apachethriftnpm/thrift: <= 0.22.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmapp connect enterprisecert_advisory90%

References

  • https://lists.apache.org/thread/pgtfq44ltc9t63kxcbqmwqzt45pnhqdy(vendor-advisory)

Related News (5 articles)

Tier B
BSI Advisories2d ago
[NEU] [mittel] IBM App Connect Enterprise (Apache Thrift): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
Rapid7 Blog46d ago
Patch Tuesday - May 2026
→ No new info (linked only)
Tier A
Microsoft MSRC51d ago
CVE-2026-43870 Apache Thrift: Node.js web_server.js multi-vulnerability
→ No new info (linked only)
Tier C
VulDB53d ago
CVE-2026-43870 | Apache Thrift up to 0.22.x web_server.js input validation
→ No new info (linked only)
Tier C
oss-security54d ago
CVE-2026-43870: Apache Thrift: Node.js web_server.js multi-vulnerability
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
0.23.0
CWECWE-22
PublishedMay 5, 2026
Trending Score43
Source articles5
Independent5
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-49486EXP
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
Trending: 59
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 45
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 42
HIGHCVE-2026-42403EXP
Apache Neethi: Circular Policy Reference Infinite Loop
Trending: 41
HIGHCVE-2026-42402EXP
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 5, 2026
Discovered by ZDM
May 5, 2026
Patch Available
May 6, 2026