CVE-2026-41605
published 2026-04-28CVE-2026-41605: Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version…
PriorityP345high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.93%
56.9th percentile
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcp3-xfwx-5hr4: Integer Overflow or Wraparound vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41605 [HIGH] CWE-190 GHSA-qcp3-xfwx-5hr4: Integer Overflow or Wraparound vulnerability in Apache Thrift
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
VulDB
Apache Thrift up to 0.22.0 Swift Compact Protocol integer overflow
vuldb·2026-04-28
CVE-2026-41605 [CRITICAL] Apache Thrift up to 0.22.0 Swift Compact Protocol integer overflow
A vulnerability described as critical has been identified in Apache Thrift up to 0.22.0. Affected by this issue is some unknown functionality of the component Swift Compact Protocol Handler. The manipulation results in integer overflow.
This vulnerability is known as CVE-2026-41605. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
Red Hat
Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
vendor_redhat·2026-04-28·CVSS 7.7
CVE-2026-41605 [HIGH] CWE-190 Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
A flaw was found in Apache Thrift. This integer overflow or wraparound vulnerability could potentially lead to unexpected behavior or resource exhaustion, which may impact the availability or integrity of the system. The exact consequences depend on how the overflow is triggered and handled within the application.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-cuda-rhel9 (R
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41605 golang-github-apache-thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability [fedora-all]
bugzilla·2026-04-30
CVE-2026-41605 [HIGH] CVE-2026-41605 golang-github-apache-thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability [fedora-all]
CVE-2026-41605 golang-github-apache-thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41605 Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
bugzilla·2026-04-28
CVE-2026-41605 [HIGH] CVE-2026-41605 Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
CVE-2026-41605 Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/4https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41605https://bugzilla.redhat.com/show_bug.cgi?id=2463418https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41605.json
2026-04-28
Published