StackRadar

CVE-2026-43869

High

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
80
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
1 of 1
affected package

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

Carried by container images the latest versions of 80 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
libthriftmaven0.9.0, 0.9.1, 0.9.2, 0.9.3+10 more0.23.062
OSV records
GHSA-7pwc-h2j2-rjgj
Also known as
BIT-thrift-2026-43869

Charts affected

80 by stars
ChartLatestAffected imagesRadar Score
opentsdbgradiant-bigdataVerified publisher0.1.71 of 6See more

opentsdb gradiant-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.23.0

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.23.0

Open the chart page →

6,147
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libthrift@0.12.0
0.23.0

Open the chart page →

4,556
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
libthrift@0.14.1
0.23.0

Open the chart page →

10,540
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
libthrift@0.15.0
0.23.0

Open the chart page →

9,920
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.23.0

Open the chart page →

8,541
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
libthrift@0.14.1
0.23.0

Open the chart page →

20,650
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
libthrift@0.13.0
0.23.0

Open the chart page →

37,671
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
libthrift@0.16.0
0.23.0

Open the chart page →

1,754
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
libthrift@0.10.0
0.23.0

Open the chart page →

43,341
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
libthrift@0.13.0
0.23.0

Open the chart page →

3,633
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
libthrift@0.9.3
0.23.0

Open the chart page →

8,540
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
libthrift@0.9.3
0.23.0

Open the chart page →

88,546
omec-control-planeopencord0.1.312 of 8See more

omec-control-plane opencord 0.1.31

2 of the 8 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
libthrift@0.9.2
0.23.0
omecproject/c3po-hssdb:master-latest28a90cc26716
libthrift@0.9.2
0.23.0

Open the chart page →

40,715
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libthrift@0.9.3
0.23.0

Open the chart page →

38,865
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
libthrift@0.9.3
0.23.0

Open the chart page →

9,606
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
libthrift@0.20.0
0.23.0

Open the chart page →

21,211
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
libthrift@0.9.1
0.23.0

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
libthrift@0.9.0
0.23.0

Open the chart page →

13,605
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
libthrift@0.14.1
0.23.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
libthrift@0.14.1
0.23.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libthrift@0.9.3-1
0.23.0

Open the chart page →

13,767
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
libthrift@0.14.2
0.23.0

Open the chart page →

1,827
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
libthrift@0.12.0
0.23.0

Open the chart page →

4,538
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

21,005
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libthrift@0.10.0
0.23.0

Open the chart page →

4,649
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
libthrift@0.14.0
0.23.0

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libthrift@0.13.0
0.23.0

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-43869.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0

Open the chart page →

22,665

Container images carrying it

62 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/cassandra:3.11.3ce85468c5bad
libthrift@0.9.2
0.23.0
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.23.0
4
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.23.0
4
library/solr:8.11.18c5f7881cebb
libthrift@0.14.1
0.23.0
3
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.23.0
2
apache/rocketmq:5.4.0319cd8a81ed1
libthrift@0.15.0
0.23.0
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.23.0
2
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.23.0
2
library/cassandra:3.11.65aa8400b4b3b
libthrift@0.9.2
0.23.0
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
libthrift@0.16.0
0.23.0
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libthrift@0.14.1
0.23.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
libthrift@0.9.3
0.23.0
1
apache/drill:1.21.11f96558fd292
libthrift@0.14.0
0.23.0
1
apache/druid:29.0.10cef139b6bf1
libthrift@0.13.0
0.23.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libthrift@0.12.0
0.23.0
1
apache/hertzbeat:1.8.075d48a62748f
libthrift@0.14.1
0.23.0
1
apache/iotdb:0.11.28647309f95d1
libthrift@0.13.0
0.23.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
libthrift@0.14.1
0.23.0
1
apache/ranger:2.7.076c176e8a0e4
libthrift@0.14.0
0.23.0
1
apache/rocketmq:5.3.0434d8398f996
libthrift@0.14.1
0.23.0
1
apache/rocketmq:4.9.35ac2a4e0f627
libthrift@0.14.1
0.23.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
libthrift@0.14.1
0.23.0
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
libthrift@0.9.2
0.23.0
1
assistiot/identity-manager_kc:latest0df4b4fa899a
libthrift@0.14.1
0.23.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
libthrift@0.9.0
0.23.0
1
bivas/presto:0.19605545994f806
libthrift@0.9.1
0.23.0
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
libthrift@0.15.0
0.23.0
1
datappeal/hive-metastore:lateste38c085a3567
libthrift@0.9.3
0.23.0
1
dbanda/livy:0.80ca125e68e53
libthrift@0.9.3
0.23.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libthrift@0.13.0
0.23.0
1
easypi/openrefine:3.7.0d2950a36a576
libthrift@0.16.0
0.23.0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
libthrift@0.13.0
0.23.0
1
gchq/accumulo:2.0.1c460bb587d6d
libthrift@0.12.0
0.23.0
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
libthrift@0.13.0
0.23.0
1
library/cassandra:3.11.598531a31f213
libthrift@0.9.2
0.23.0
1
library/cassandra:3.11.10b095ff3248c6
libthrift@0.9.2
0.23.0
1
library/cassandra:2.1.20cb079c0d7a57
libthrift@0.9.2
0.23.0
1
library/solr:8.7.0d124efd81fbb
libthrift@0.13.0
0.23.0
1
library/storm:2.4.0bd5d420506d6
libthrift@0.13.0
0.23.0
1
lightbend/spark-history-server:2.4.00bedf37f428a
libthrift@0.9.3
0.23.0
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
libthrift@0.10.0
0.23.0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libthrift@0.9.3
0.23.0
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libthrift@0.9.2
0.23.0
1
omecproject/onos-progran:1.0.05715e5648aa0
libthrift@0.9.3
0.23.0
1
openzipkin/zipkin:2.24197a9692f6a9
libthrift@0.15.0
0.23.0
1
openzipkin/zipkin:2.21.060c3970df479
libthrift@0.13.0
0.23.0
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
libthrift@0.12.0
0.23.0
1
owasp/dependency-track:3.8.0efc65e702ee1
libthrift@0.13.0
0.23.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
libthrift@0.9.3
0.23.0
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
libthrift@0.9.3
0.23.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.