Skip to content

chore(deps): update module github.com/apache/thrift to v0.23.0 [security] (release-v2.9) - #7119

Merged
renovate-sh-app[bot] merged 1 commit into
release-v2.9from
renovate/release-v2.9-go-github.com-apache-thrift-vulnerability
May 6, 2026
Merged

chore(deps): update module github.com/apache/thrift to v0.23.0 [security] (release-v2.9)#7119
renovate-sh-app[bot] merged 1 commit into
release-v2.9from
renovate/release-v2.9-go-github.com-apache-thrift-vulnerability

Conversation

@renovate-sh-app

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/apache/thrift v0.22.0v0.23.0 age confidence

Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability

BIT-thrift-2026-41602 / CVE-2026-41602 / GHSA-wf45-q9ch-q8gh

More information

Details

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

apache/thrift (github.com/apache/thrift)

v0.23.0: Version 0.23.0

Compare Source

Please head over to the official release download source:
http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

…ity]

| datasource | package                  | from    | to      |
| ---------- | ------------------------ | ------- | ------- |
| go         | github.com/apache/thrift | v0.22.0 | v0.23.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app Bot added dependencies Pull requests that update a dependency file gomod minor renovate Applied to PR's created by renovatebot security update-minor labels May 6, 2026
@renovate-sh-app
renovate-sh-app Bot requested review from yvrhdn and zalegrala as code owners May 6, 2026 23:11
@renovate-sh-app renovate-sh-app Bot added the renovate Applied to PR's created by renovatebot label May 6, 2026
@renovate-sh-app renovate-sh-app Bot added the minor label May 6, 2026
@renovate-sh-app
renovate-sh-app Bot enabled auto-merge (squash) May 6, 2026 23:11
@renovate-sh-app
renovate-sh-app Bot merged commit 65d8d70 into release-v2.9 May 6, 2026
36 checks passed
@renovate-sh-app
renovate-sh-app Bot deleted the renovate/release-v2.9-go-github.com-apache-thrift-vulnerability branch May 6, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file gomod minor renovate Applied to PR's created by renovatebot security update-minor

0 participants