Junglewise Threat Intelligence

CVE-2026-41605: Apache Thrift integer overflow in Swift Compact Protocol

CVE-2026-41605 · Severity: high · CVSS 7.3 · Published 2026-04-28

Technologies: Apache Thrift, Red Hat Multicluster Global Hub. Vendors: Apache, Red Hat.

Executive brief

Apache Thrift, a framework for cross-language software development, contains a flaw that can lead to system instability. An attacker could exploit this vulnerability to cause resource exhaustion or unexpected behavior, potentially resulting in a service outage or impacting data integrity. This affects various enterprise products that rely on Thrift for communication, including certain Red Hat OpenShift and cluster management tools.

Technical details

An integer overflow or wraparound vulnerability exists in Apache Thrift's Swift Compact Protocol implementation prior to version 0.23.0. The flaw occurs during the handling of integer operations, which can be triggered by a remote, unauthenticated attacker sending specially crafted input over the network. Successful exploitation can lead to resource exhaustion, unexpected system behavior, or a denial-of-service (DoS) condition, impacting the availability and integrity of the affected service. Red Hat has identified several downstream products, such as OpenShift distributed tracing and Multicluster Global Hub, as affected due to their use of the vulnerable library. Users are advised to upgrade to Apache Thrift 0.23.0 or apply vendor-specific patches.

Affected products

  • Apache Thrift before 0.23.0
  • Red Hat Multicluster Global Hub 1.3.4, 1.4.5, 1.5.4, 1.6.2
  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • Red Hat OpenShift distributed tracing (Tempo) 3.9.3

Timeline

  • 2026-04-28: disclosed: Initial disclosure by Apache Software Foundation and Openwall mailing list.
  • 2026-04-28: advisory: CVE-2026-41605 published.
  • 2026-05-07: patched: Red Hat released security advisory RHSA-2026:14885 for OpenShift distributed tracing.

References

Related threats