CVE-2026-41606
published 2026-04-28CVE-2026-41606: Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.10%
62.0th percentile
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Thrift up to 0.22.0 c_glib stack-based overflow
vuldb·2026-04-28
CVE-2026-41606 [CRITICAL] Apache Thrift up to 0.22.0 c_glib stack-based overflow
A vulnerability classified as critical has been found in Apache Thrift up to 0.22.0. This affects an unknown part of the component c_glib. This manipulation causes stack-based buffer overflow.
This vulnerability is handled as CVE-2026-41606. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-h5hj-56h4-rwcp: Uncontrolled Recursion vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41606 [MEDIUM] CWE-674 GHSA-h5hj-56h4-rwcp: Uncontrolled Recursion vulnerability in Apache Thrift
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Red Hat
Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
vendor_redhat·2026-04-28·CVSS 7.5
CVE-2026-41606 [HIGH] CWE-606 Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
A flaw was found in Apache Thrift. An uncontrolled recursion vulnerability exists, which could allow a remote attacker to trigger a Denial of Service (DoS) condition. This occurs when the affected component processes specially crafted input, leading to excessive resource consumption and system unavailability.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Not affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-cuda-rhel9 (Re
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41606 golang-github-apache-thrift: Apache Thrift: Denial of Service via uncontrolled recursion [fedora-all]
bugzilla·2026-04-29
CVE-2026-41606 [HIGH] CVE-2026-41606 golang-github-apache-thrift: Apache Thrift: Denial of Service via uncontrolled recursion [fedora-all]
CVE-2026-41606 golang-github-apache-thrift: Apache Thrift: Denial of Service via uncontrolled recursion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41606 Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
bugzilla·2026-04-28
CVE-2026-41606 [HIGH] CVE-2026-41606 Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
CVE-2026-41606 Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/3https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41606https://bugzilla.redhat.com/show_bug.cgi?id=2463408https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41606.json
2026-04-28
Published