CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift (Rust implementation)to a version that resolves this vulnerability.Fixed in 0.23.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43868?
CVE-2026-43868 is classified as a vulnerability that can lead to memory allocation issues, posing potential risks to affected systems.
How do I fix CVE-2026-43868?
To fix CVE-2026-43868, users should upgrade to Apache Thrift version 0.23.0 or later.
What versions of Apache Thrift are affected by CVE-2026-43868?
CVE-2026-43868 affects Apache Thrift versions prior to 0.23.0.
What is the nature of the issue in CVE-2026-43868?
CVE-2026-43868 involves a pattern memory allocation vulnerability that can be exploited with excessive size values.
Is there a workaround for CVE-2026-43868?
There are no known workarounds for CVE-2026-43868; upgrading to the fixed version is recommended.