Apache Thrift Origin Validation Error and Path Traversal Vulnerability

Vulnerability

A vulnerability in Apache Thrift prior to version 0.23.0 allows for origin validation errors, improper limitation of pathnames leading to path traversal, improper neutralization of CRLF sequences in HTTP headers causing HTTP request/response splitting, and uncontrolled resource consumption.

Impact

Exploitation of this vulnerability could lead to path traversal, allowing attackers to access restricted directories, and HTTP request/response splitting, which could be used to manipulate HTTP responses or requests.

Remediation

Users are advised to upgrade to Apache Thrift version 0.23.0 or later, which addresses this vulnerability.

Added: May 5, 2026, 9:19 AM
Updated: May 5, 2026, 9:19 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
1.9
exploitability
5.4
remediation
7.7
relevance
7.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.