Skip to content

Commit 37837e7

Browse files
fix(deps): Update module github.com/apache/thrift to v0.23.0 [SECURITY] (#748)
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/apache/thrift](https://redirect.github.com/apache/thrift) | `v0.22.0` → `v0.23.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fapache%2fthrift/v0.23.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fapache%2fthrift/v0.22.0/v0.23.0?slim=true) | --- ### Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability [CVE-2026-41602](https://nvd.nist.gov/vuln/detail/CVE-2026-41602) / [GHSA-wf45-q9ch-q8gh](https://redirect.github.com/advisories/GHSA-wf45-q9ch-q8gh) <details> <summary>More information</summary> #### Details Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2026-41602](https://nvd.nist.gov/vuln/detail/CVE-2026-41602) - [https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql](https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql) - [http://www.openwall.com/lists/oss-security/2026/04/28/6](http://www.openwall.com/lists/oss-security/2026/04/28/6) - [https://github.com/advisories/GHSA-wf45-q9ch-q8gh](https://redirect.github.com/advisories/GHSA-wf45-q9ch-q8gh) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-wf45-q9ch-q8gh) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>apache/thrift (github.com/apache/thrift)</summary> ### [`v0.23.0`](https://redirect.github.com/apache/thrift/releases/tag/v0.23.0): Version 0.23.0 [Compare Source](https://redirect.github.com/apache/thrift/compare/v0.22.0...v0.23.0) Please head over to the official release download source: <http://thrift.apache.org/download> The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNDAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE0MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJzZWN1cml0eSJdfQ==-->
1 parent cde4439 commit 37837e7

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ require (
1515

1616
require (
1717
github.com/andybalholm/brotli v1.2.1 // indirect
18-
github.com/apache/thrift v0.22.0 // indirect
18+
github.com/apache/thrift v0.23.0 // indirect
1919
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
2020
github.com/bahlo/generic-list-go v0.2.0 // indirect
2121
github.com/buger/jsonparser v1.1.2 // indirect

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ github.com/andybalholm/brotli v1.2.1 h1:R+f5xP285VArJDRgowrfb9DqL18yVK0gKAW/F+eT
33
github.com/andybalholm/brotli v1.2.1/go.mod h1:rzTDkvFWvIrjDXZHkuS16NPggd91W3kUSvPlQ1pLaKY=
44
github.com/apache/arrow-go/v18 v18.6.0 h1:GX/Jyd3R7mCLiECAwY9FWbbaYblie2WXBSz4Sw8fNpM=
55
github.com/apache/arrow-go/v18 v18.6.0/go.mod h1:gm3MiPpY82fLYK5VKPB3WoJbsiLVDfT7flD5/vHReKw=
6-
github.com/apache/thrift v0.22.0 h1:r7mTJdj51TMDe6RtcmNdQxgn9XcyfGDOzegMDRg47uc=
7-
github.com/apache/thrift v0.22.0/go.mod h1:1e7J/O1Ae6ZQMTYdy9xa3w9k+XHWPfRvdPyJeynQ+/g=
6+
github.com/apache/thrift v0.23.0 h1:wKR6YnefQSEnxpEfmgTPuJibNG4bF0p2TK34tHLWi3s=
7+
github.com/apache/thrift v0.23.0/go.mod h1:zPt6WxgvTOM6hF92y8C+MkEM5LMxZuk4JcQOiU4Esvs=
88
github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ=
99
github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk=
1010
github.com/bahlo/generic-list-go v0.2.0 h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk=

0 commit comments

Comments
 (0)