CVE Vulnerabilities

CVE-2026-43868

Memory Allocation with Excessive Size Value

Published: May 05, 2026 | Modified: Jul 21, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

NameVendorStart VersionEnd Version
ThriftApache*0.23.0 (excluding)
Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1RedHatlibthrift*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-modelmesh-rhel9:1783443816*
ThriftUbuntuquesting*

Potential Mitigations

References