logo

Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws

ID: 3d2403a6-27f1-58b1-9f53-47d1d1a5e967

STIX ID: report--3d2403a6-27f1-58b1-9f53-47d1d1a5e967

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Apache Thrift published a security update addressing multiple vulnerabilities across most language bindings — notably a critical Java TSSLTransportFactory certificate validation failure (CVE-2026-41603) enabling MitM, plus memory-corruption, integer overflow, out-of-bounds reads, and recursion/DoS issues affecting C/glib, C++, Go, Node.js, and Swift; users running versions prior to 0.23.0 are advised to upgrade to 0.23.0 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.