Skip to content

[TT-17190] Merging to release-5.13: [TT-17190] Upgrade apache/thrift to 0.23.0 (#8194)#8196

Merged
MFCaballero merged 1 commit into
release-5.13from
merge/release-5.13/264866261fce424c04cb10055670ef6ca84f45ca/TT-17190
May 11, 2026
Merged

[TT-17190] Merging to release-5.13: [TT-17190] Upgrade apache/thrift to 0.23.0 (#8194)#8196
MFCaballero merged 1 commit into
release-5.13from
merge/release-5.13/264866261fce424c04cb10055670ef6ca84f45ca/TT-17190

Conversation

@probelabs

@probelabs probelabs Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor

TT-17190 Upgrade apache/thrift to 0.23.0 (#8194)

Description

Fix CVE-160: CVE-2026-41602 -> Requires Apache Thrift 0.23.0

Related Issue

Motivation and Context

How This Has Been Tested

Screenshots (if appropriate)

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing
    functionality to change)
  • Refactoring or add test (improvements in base code or adds test
    coverage to functionality)

Checklist

  • I ensured that the documentation is up to date
  • I explained why this PR updates go.mod in detail with reasoning
    why it's required
  • I would like a code coverage CI quality gate exception and have
    explained why

Ticket Details

TT-17190
Status In Code Review
Summary Additional CVE fixes (Gateway & Dashboard)

Generated at: 2026-05-11 18:37:00

<!-- Provide a general summary of your changes in the Title above -->

## Description
Fix CVE-160: CVE-2026-41602 -> Requires Apache Thrift 0.23.0

## Related Issue

<!-- This project only accepts pull requests related to open issues. -->
<!-- If suggesting a new feature or change, please discuss it in an
issue first. -->
<!-- If fixing a bug, there should be an issue describing it with steps
to reproduce. -->
<!-- OSS: Please link to the issue here. Tyk: please create/link the
JIRA ticket. -->

## Motivation and Context

<!-- Why is this change required? What problem does it solve? -->

## How This Has Been Tested

<!-- Please describe in detail how you tested your changes -->
<!-- Include details of your testing environment, and the tests -->
<!-- you ran to see how your change affects other areas of the code,
etc. -->
<!-- This information is helpful for reviewers and QA. -->

## Screenshots (if appropriate)

## Types of changes

<!-- What types of changes does your code introduce? Put an `x` in all
the boxes that apply: -->

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Refactoring or add test (improvements in base code or adds test
coverage to functionality)

## Checklist

<!-- Go over all the following points, and put an `x` in all the boxes
that apply -->
<!-- If there are no documentation updates required, mark the item as
checked. -->
<!-- Raise up any additional concerns not covered by the checklist. -->

- [ ] I ensured that the documentation is up to date
- [ ] I explained why this PR updates go.mod in detail with reasoning
why it's required
- [ ] I would like a code coverage CI quality gate exception and have
explained why

<!---TykTechnologies/jira-linter starts here-->

### Ticket Details

<details>
<summary>
<a href="https://tyktech.atlassian.net/browse/TT-17190" title="TT-17190"
target="_blank">TT-17190</a>
</summary>

|         |    |
|---------|----|
| Status  | In Dev |
| Summary | Additional CVE fixes (Gateway & Dashboard) |

Generated at: 2026-05-11 15:48:19

</details>

<!---TykTechnologies/jira-linter ends here-->

(cherry picked from commit 2648662)
@probelabs

probelabs Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor Author

This pull request upgrades github.com/apache/thrift from v0.22.0 to v0.23.0 to address security vulnerability CVE-2026-41602.

Files Changed Analysis

The change is limited to updating the version of the apache/thrift dependency in go.mod and its corresponding checksum in go.sum. This is a direct dependency bump with no other code modifications.

Architecture & Impact Assessment

  • What this PR accomplishes: Mitigates CVE-2026-41602 by upgrading a transitive dependency.
  • Key technical changes introduced: The version of github.com/apache/thrift is updated to v0.23.0.
  • Affected system components: The apache/thrift library is an indirect dependency used by the Jaeger client (github.com/uber/jaeger-client-go) for its communication protocol. Therefore, this upgrade directly impacts the distributed tracing feature when Jaeger is used as the backend. The change could potentially affect the serialization and transmission of trace data from the gateway to the Jaeger collector.
graph TD
    A[Tyk Gateway] -->|uses| B(Distributed Tracing Module)
    B -->|integrates with| C(uber/jaeger-client-go)
    C -->|depends on for transport| D(apache/thrift)
    D -- PR updates --> E(apache/thrift v0.23.0)
Loading

Scope Discovery & Context Expansion

The direct scope is a minimal dependency version change. However, the functional impact is concentrated on the Jaeger tracing integration. Any breaking changes or subtle incompatibilities in the new version of thrift could disrupt the gateway's ability to export trace data. Verification should focus on ensuring that with Jaeger tracing enabled, spans are correctly generated, transmitted, and appear in the Jaeger UI without errors. The primary integration point in the codebase is within the tyk/trace/jaeger/ directory.

Metadata
  • Review Effort: 1 / 5
  • Primary Label: chore

Powered by Visor from Probelabs

Last updated: 2026-05-11T17:28:14.110Z | Triggered by: pr_opened | Commit: a01248b

💡 TIP: You can chat with Visor using /visor ask <your question>

@probelabs

probelabs Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor Author

✅ Security Check Passed

No security issues found – changes LGTM.

✅ Security Check Passed

No security issues found – changes LGTM.

\n\n \n\n

✅ Performance Check Passed

No performance issues found – changes LGTM.

✅ Quality Check Passed

No quality issues found – changes LGTM.


Powered by Visor from Probelabs

Last updated: 2026-05-11T17:28:07.134Z | Triggered by: pr_opened | Commit: a01248b

💡 TIP: You can chat with Visor using /visor ask <your question>

@MFCaballero MFCaballero added the deps-reviewed Dependency changes reviewed and approved for CI execution label May 11, 2026
@MFCaballero MFCaballero changed the title Merging to release-5.13: [TT-17190] Upgrade apache/thrift to 0.23.0 (#8194) [TT-17190] Merging to release-5.13: [TT-17190] Upgrade apache/thrift to 0.23.0 (#8194) May 11, 2026
@MFCaballero
MFCaballero enabled auto-merge (squash) May 11, 2026 18:40
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@MFCaballero
MFCaballero merged commit 0be87ee into release-5.13 May 11, 2026
64 of 71 checks passed
@MFCaballero
MFCaballero deleted the merge/release-5.13/264866261fce424c04cb10055670ef6ca84f45ca/TT-17190 branch May 11, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deps-reviewed Dependency changes reviewed and approved for CI execution

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant