CVE-2026-41604
published 2026-04-28CVE-2026-41604: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which…
PriorityP347high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
0.92%
56.5th percentile
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Thrift up to 0.22.0 skip denial of service
vuldb·2026-04-28
CVE-2026-41604 [LOW] Apache Thrift up to 0.22.0 skip denial of service
A vulnerability marked as problematic has been reported in Apache Thrift up to 0.22.0. Affected by this vulnerability is the function skip. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-41604. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-r4rx-ffxv-23vw: Out-of-bounds Read vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41604 [HIGH] CWE-125 GHSA-r4rx-ffxv-23vw: Out-of-bounds Read vulnerability in Apache Thrift
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Red Hat
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
vendor_redhat·2026-04-28·CVSS 8.2
CVE-2026-41604 [HIGH] CWE-125 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
A flaw was found in Apache Thrift. This out-of-bounds read vulnerability could allow an attacker to access memory outside of allocated bounds. This could lead to information disclosure or potentially a denial of service (DoS) condition.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-cuda-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-rocm
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41604 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
bugzilla·2026-04-30
CVE-2026-41604 [HIGH] CVE-2026-41604 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
CVE-2026-41604 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41604 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
bugzilla·2026-04-28
CVE-2026-41604 [HIGH] CVE-2026-41604 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
CVE-2026-41604 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/5https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41604https://bugzilla.redhat.com/show_bug.cgi?id=2463416https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41604.json
2026-04-28
Published