VDB
CVE-2026-43868
CVE-2026-43868
PUBLISHED
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
EPSS 0.71% · 50.7th percentile
Risk Scores
EPSS Score
0.71%
50.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Thrift | 0 |
Timeline
- May 5, 2026 CVE Published
- May 5, 2026 PoC Published
- May 5, 2026 PoC Published
- May 8, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
References
- https://lists.apache.org/thread/zj76dtwnbbs1m7z3focf4wd51pqpsmn9 vendor-advisory