Junglewise Threat Intelligence

CVE-2026-41604: Apache Thrift out-of-bounds read in Swift Range skip function

CVE-2026-41604 · Severity: high · CVSS 8.2 · Published 2026-04-28

Technologies: Red Hat Multicluster Global Hub, Apache Thrift. Vendors: Red Hat, Apache.

Executive brief

Apache Thrift, a framework for scalable cross-language services development, is vulnerable to a memory handling flaw. An attacker can exploit this to access restricted memory, potentially leading to the exposure of sensitive information or causing the service to crash. This impact can disrupt business operations and compromise data confidentiality in applications using the Thrift library.

Technical details

An out-of-bounds read vulnerability exists in Apache Thrift before version 0.23.0, specifically identified in the Swift Range skip() function. The flaw is caused by insufficient validation of memory access boundaries when processing specially crafted input. A remote, unauthenticated attacker can exploit this over the network to read memory outside of allocated buffers. This can result in the disclosure of sensitive data residing in memory or trigger a crash (Denial of Service). The issue is resolved in Apache Thrift version 0.23.0.

Affected products

  • Apache Thrift before 0.23.0
  • Red Hat Multicluster Global Hub 1.3.4, 1.4.5, 1.5.4, 1.6.2
  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • Red Hat OpenShift distributed tracing (Tempo) 3.9.3

Timeline

  • 2026-04-28: disclosed: Initial disclosure and CVE assignment
  • 2026-04-28: patched: Apache Thrift version 0.23.0 released
  • 2026-05-07: advisory: Red Hat security advisory RHSA-2026:14885 published

References

Related threats