CVE-2026-43870 | Apache Thrift up to 0.22.x web_server.js input validation
A vulnerability, which was classified as critical, has been found in Apache Thrift up to 0.22.x. The affected element is an unknown function of the file web_server.js. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2026-43870. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.