Skip to content

Update thrift to 0.23.0 to eliminate warnings about CVE-2026-43870 #3572

@steveloughran

Description

@steveloughran

Describe the enhancement requested

There'a a new thrift release with a CVE associated with the RPC code.

Parquet is not exposed to this, but thrift gets onto the classpath and all CVE scanners will be complaining about the version being vulnerable to CVE-2026-43870.

Component(s)

Build

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions