Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
ID: 3d2403a6-27f1-58b1-9f53-47d1d1a5e967
STIX ID: report--3d2403a6-27f1-58b1-9f53-47d1d1a5e967
Feed Name: securityonline.info
Threat Score
Apache Thrift published a security update addressing multiple vulnerabilities across most language bindings — notably a critical Java TSSLTransportFactory certificate validation failure (CVE-2026-41603) enabling MitM, plus memory-corruption, integer overflow, out-of-bounds reads, and recursion/DoS issues affecting C/glib, C++, Go, Node.js, and Swift; users running versions prior to 0.23.0 are advised to upgrade to 0.23.0 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
