{
  "threat_severity" : "Important",
  "public_date" : "2026-05-05T07:45:35Z",
  "bugzilla" : {
    "description" : "apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities",
    "id" : "2466671",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2466671"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.\nThis issue affects Apache Thrift: before 0.23.0.\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.", "A flaw was found in Apache Thrift. This vulnerability encompasses an origin validation error, improper limitation of a pathname to a restricted directory (path traversal), and improper neutralization of CRLF sequences in HTTP headers (HTTP request/response splitting). A remote attacker could exploit these issues to trigger uncontrolled resource consumption, leading to a Denial of Service (DoS) condition. Furthermore, path traversal could allow unauthorized access to files, and HTTP request/response splitting might enable other web-based attacks." ],
  "statement" : "This Important flaw in Apache Thrift allows a remote attacker to trigger a denial of service through uncontrolled resource consumption. Additionally, the vulnerability enables path traversal for unauthorized file access and HTTP request/response splitting, potentially leading to further web-based attacks in Red Hat products that integrate Apache Thrift.",
  "affected_release" : [ {
    "product_name" : "Multicluster Global Hub 1.4.5",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:41030",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681"
  }, {
    "product_name" : "Multicluster Global Hub 1.5.6",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42852",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784562060"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.14",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36882",
    "cpe" : "cpe:/a:redhat:acm:2.14::el9",
    "package" : "rhacm2/acm-grafana-rhel9:1782693386"
  } ],
  "package_state" : [ {
    "product_name" : "Cryostat 4",
    "fix_state" : "Not affected",
    "package_name" : "cryostat/cryostat-storage-rhel9",
    "cpe" : "cpe:/a:redhat:cryostat:4"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Out of support scope",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "OpenShift Service Mesh 2",
    "fix_state" : "Not affected",
    "package_name" : "openshift-service-mesh/istio-rhel8-operator",
    "cpe" : "cpe:/a:redhat:service_mesh:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Out of support scope",
    "package_name" : "redhat-user-workloads/grafana-acm-212",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "redhat-user-workloads/grafana-acm-213",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaiis/vllm-cpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaiis/vllm-tpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat build of Apache Camel 4 for Quarkus 3",
    "fix_state" : "Not affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:camel_quarkus:3"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "opentelemetry-collector",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "opentelemetry-collector",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-modelmesh-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-model-registry-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Under investigation",
    "package_name" : "openshift4/cnf-tests-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/oc-mirror-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Under investigation",
    "package_name" : "openshift4/ztp-site-generate-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "redhat-user-workloads/cnf-tests-4-15",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "redhat-user-workloads/ztp-site-generate-4-15",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "redhat-user-workloads/ztp-site-generate-4-16",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/opentelemetry-collector-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/tempo-jaeger-query-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/tempo-query-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/tempo-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Not affected",
    "package_name" : "rhoso-operators/openstack-operator-bundle",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Will not fix",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-43870\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43870\nhttps://lists.apache.org/thread/pgtfq44ltc9t63kxcbqmwqzt45pnhqdy" ],
  "name" : "CVE-2026-43870",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}