CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern

Published May 5, 2026
·
Updated

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Affected Software

2 affected components
Apache Thrift (Rust)<0.23.0
Apache Thrift<0.23.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Thrift (Rust implementation) to a version that resolves this vulnerability.

    Fixed in 0.23.0

Event History

May 5, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Data Sourced
via Red Hat·09:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Jan 25, 58467
Event
via NVD·03:38 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-43868?

CVE-2026-43868 is classified as a vulnerability that can lead to memory allocation issues, posing potential risks to affected systems.

2

How do I fix CVE-2026-43868?

To fix CVE-2026-43868, users should upgrade to Apache Thrift version 0.23.0 or later.

3

What versions of Apache Thrift are affected by CVE-2026-43868?

CVE-2026-43868 affects Apache Thrift versions prior to 0.23.0.

4

What is the nature of the issue in CVE-2026-43868?

CVE-2026-43868 involves a pattern memory allocation vulnerability that can be exploited with excessive size values.

5

Is there a workaround for CVE-2026-43868?

There are no known workarounds for CVE-2026-43868; upgrading to the fixed version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203