CVE-2026-58023
published 2026-07-27CVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.64%
48.1th percentile
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-58023 [MEDIUM] CWE-125 Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x out-of-bounds
vuldb·2026-07-26
CVE-2026-58023 [LOW] Apache Thrift up to 0.23.x out-of-bounds
A vulnerability was found in Apache Thrift up to 0.23.x. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-58023. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
Red Hat
thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read
vendor_redhat·2026-07-27·CVSS 9.1
CVE-2026-58023 [CRITICAL] CWE-125 thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read
thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read
A flaw was found in Apache Thrift c_glib bindings. This out-of-bounds read vulnerability allows an attacker to potentially access sensitive information or cause a denial of service. The vulnerability occurs when the software attempts to read data beyond the allocated memory buffer.
Statement: This Moderate severity out-of-bounds read vulnerability in Apache Thrift c_glib bindings could lead to information disclosure and denial of service. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected where they utilize vulnerable versions of Apache Thrift. Red Hat Enterprise Linux AI is not affected as the vulnerable cod
No detection rules found.
No public exploits indexed.
2026-07-27
Published