CVE-2026-41607
published 2026-04-28CVE-2026-41607: Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
0.90%
55.9th percentile
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
vendor_redhat9.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7gqw-825c-3842: Out-of-bounds Read vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41607 [MEDIUM] CWE-125 GHSA-7gqw-825c-3842: Out-of-bounds Read vulnerability in Apache Thrift
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
VulDB
Apache Thrift up to 0.22.0 C++ JSON out-of-bounds
vuldb·2026-04-28
CVE-2026-41607 [LOW] Apache Thrift up to 0.22.0 C++ JSON out-of-bounds
A vulnerability classified as problematic was found in Apache Thrift up to 0.22.0. This vulnerability affects unknown code of the component C++ JSON Handler. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-41607. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
Red Hat
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
vendor_redhat·2026-04-28·CVSS 9.1
CVE-2026-41607 [HIGH] CWE-125 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
A flaw was found in Apache Thrift. This out-of-bounds read vulnerability can lead to the disclosure of sensitive information or a denial of service.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-cuda-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-rocm-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-tpu-rhel9 (Red Hat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41607 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
bugzilla·2026-04-30
CVE-2026-41607 [CRITICAL] CVE-2026-41607 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
CVE-2026-41607 golang-github-apache-thrift: Apache Thrift: Out-of-bounds Read vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41607 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
bugzilla·2026-04-28
CVE-2026-41607 [HIGH] CVE-2026-41607 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
CVE-2026-41607 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/2https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41607https://bugzilla.redhat.com/show_bug.cgi?id=2463412https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41607.json
2026-04-28
Published