← All tasks
pythondatabricks/databricks-sql-python #783Not a task: already works

Release new version with thrift >=0.23.0 support (6 critical CVEs fixed)

envgap__databricks__databricks-sql-python-783

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
c3cae639a8998ba301593fefb8e4a6d4fdfc50db
Manifest
pyproject.toml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

databricks/databricks-sql-python #783 · read the original issue
Apache Thrift 0.23.0 was released on April 27, 2026 and fixes 6 High-severity CVEs (CVE-2026-41636, CVE-2026-41605, CVE-2026-41604, CVE-2026-41603, CVE-2026-41602, CVE-2025-48431). All prior versions are affected.

`databricks-sql-connector 4.2.6` currently requires `thrift >=0.22.0, <0.23.0`, which prevents downstream consumers from picking up the security fix. The thrift 0.23.0 Python library has no breaking API changes -- it adds security hardening (recursion depth limits, payload size limits) and drops EOL Python versions.

**Requests:**

1. **Short-term:** Widen the pin in the current codebase to `thrift >=0.22.0, <0.24.0` to allow 0.23.0
2. **Release:** Publish a new version (4.2.7 or 4.3.0) to PyPI so downstream consumers can resolve the CVEs

Many enterprise users are blocked on security scan SLAs and cannot remediate until this is unblocked. Thrift 0.23.0 is also not yet on PyPI, but once it is, having the pin already widened would unblock everyone immediately.

Related: #695, PR #733
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]