StackRadar

CVE-2026-43869

High

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
80
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
1 of 1
affected package

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

Carried by container images the latest versions of 80 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
libthriftmaven0.9.0, 0.9.1, 0.9.2, 0.9.3+10 more0.23.062
OSV records
GHSA-7pwc-h2j2-rjgj
Also known as
BIT-thrift-2026-43869

Charts affected

80 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libthrift@0.14.1
0.23.0

Open the chart page →

7,713
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
libthrift@0.15.0
0.23.0

Open the chart page →

6,328
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
libthrift@0.13.0
0.23.0

Open the chart page →

3,229
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.23.0

Open the chart page →

3,812
temporallemontechVerified publisher0.37.01 of 13See more

temporal lemontech 0.37.0

1 of the 13 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

14,893
sparkmicrosoft1.0.41 of 3See more

spark microsoft 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
libthrift@0.9.3
0.23.0

Open the chart page →

13,738
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
libthrift@0.13.0
0.23.0

Open the chart page →

6,048
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
libthrift@0.13.0
0.23.0

Open the chart page →

7,930
zipkinygqygq2Verified publisher2.1.41 of 4See more

zipkin ygqygq2 2.1.4

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.24197a9692f6a9
libthrift@0.15.0
0.23.0

Open the chart page →

2,764
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
libthrift@0.14.1
0.23.0

Open the chart page →

14,000
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
libthrift@0.9.3
0.23.0

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.23.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.23.0

Open the chart page →

20,837
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
libthrift@0.16.0
0.23.0

Open the chart page →

4,641
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
libthrift@0.14.1
0.23.0

Open the chart page →

9,154
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
libthrift@0.9.3
0.23.0

Open the chart page →

7,335
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
libthrift@0.15.0
0.23.0

Open the chart page →

6,328
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
libthrift@0.9.3
0.23.0

Open the chart page →

8,198
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
libthrift@0.14.0
0.23.0

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
libthrift@0.9.2
0.23.0

Open the chart page →

17,896
hbasedmwm-bigdataVerified publisher0.1.61 of 5See more

hbase dmwm-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.23.0

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.23.0

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.71 of 6See more

opentsdb dmwm-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.23.0

Open the chart page →

17,511
temporalglasskubeVerified publisher0.45.2-gk.11 of 14See more

temporal glasskube 0.45.2-gk.1

1 of the 14 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

16,346
hbasegradiant-bigdataVerified publisher0.1.61 of 5See more

hbase gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.23.0

Open the chart page →

13,392
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
libthrift@0.13.0
0.23.0

Open the chart page →

6,165
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libthrift@0.9.3
0.23.0

Open the chart page →

12,019
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
libthrift@0.14.1
0.23.0

Open the chart page →

7,710
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
libthrift@0.14.1
0.23.0

Open the chart page →

24,930
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
libthrift@0.13.0
0.23.0

Open the chart page →

2,269
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libthrift@0.12.0
0.23.0

Open the chart page →

7,835
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libthrift@0.14.1
0.23.0

Open the chart page →

7,713
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
libthrift@0.13.0
0.23.0

Open the chart page →

5,277
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
libthrift@0.14.1
0.23.0

Open the chart page →

13,352
jaegerbook-k8sinfra-v23.4.01 of 5See more

jaeger book-k8sinfra-v2 3.4.0

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.65aa8400b4b3b
libthrift@0.9.2
0.23.0

Open the chart page →

19,229
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
libthrift@0.9.2
0.23.0

Open the chart page →

9,473
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

16,198
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.598531a31f213
libthrift@0.9.2
0.23.0

Open the chart page →

12,018
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
libthrift@0.9.1
0.23.0

Open the chart page →

7,226
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
libthrift@0.9.3
0.23.0

Open the chart page →

14,066
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
libthrift@0.13.0
0.23.0

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.23.0

Open the chart page →

6,147
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

20,205
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
libthrift@0.9.3
0.23.0

Open the chart page →

5,639
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
libthrift@0.16.0
0.23.0

Open the chart page →

3,463
accumulogaffer2.2.11 of 4See more

accumulo gaffer 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
libthrift@0.12.0
0.23.0

Open the chart page →

16,892
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
libthrift@0.14.1
0.23.0

Open the chart page →

4,921
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
libthrift@0.13.0
0.23.0

Open the chart page →

34,754
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.65aa8400b4b3b
libthrift@0.9.2
0.23.0

Open the chart page →

19,229
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.23.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.23.0

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.23.0

Open the chart page →

6,882

Container images carrying it

62 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
libthrift@0.13.0
0.23.0
1
sslhep/hive-metastore:3.1.39e80af083079
libthrift@0.9.3
0.23.0
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
libthrift@0.14.2
0.23.0
1
trinodb/trino:45038c6f24ab1a4
libthrift@0.20.0
0.23.0
1
trinodb/trino:405ee80ab5eeab2
libthrift@0.9.3-1
0.23.0
1
xetusoss/archiva:v2.2.588f25242b9ee
libthrift@0.9.1
0.23.0
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
libthrift@0.14.1
0.23.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libthrift@0.12.0
0.23.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
libthrift@0.9.3
0.23.0
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libthrift@0.10.0
0.23.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libthrift@0.9.3
0.23.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libthrift@0.13.0
0.23.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.