Executive brief
Apache Thrift, a framework for scalable cross-language services development, is vulnerable to a memory handling flaw. An attacker can exploit this to read sensitive information from the system's memory or cause the service to crash, leading to a denial of service. This affects various enterprise products that integrate Thrift, including Red Hat OpenShift and Advanced Cluster Management.
Technical details
An out-of-bounds (OOB) read vulnerability exists in Apache Thrift's C++ JSON protocol implementation. The flaw occurs when the library processes specially crafted input, failing to properly validate memory access boundaries. A remote, unauthenticated attacker can exploit this via the network to access memory outside of allocated buffers. This can result in the disclosure of sensitive information or trigger a crash (Denial of Service). The issue is resolved in Apache Thrift version 0.23.0. Red Hat has also issued several security advisories (e.g., RHSA-2026:14885) for downstream products incorporating the vulnerable library.
Affected products
- Apache Thrift before 0.23.0
- Red Hat Multicluster Global Hub 1.3.4, 1.4.5, 1.5.4, 1.6.2
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat OpenShift distributed tracing 3.9.3
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift Container Platform 4
Timeline
- 2026-04-27: disclosed: Initial disclosure on oss-security mailing list
- 2026-04-28: advisory: NVD publication date
- 2026-05-07: patched: Red Hat released security advisory RHSA-2026:14885
References
- https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql
- http://www.openwall.com/lists/oss-security/2026/04/28/2
- https://access.redhat.com/errata/RHSA-2026:14885
- https://access.redhat.com/errata/RHSA-2026:21769
- https://access.redhat.com/errata/RHSA-2026:22347
- https://access.redhat.com/errata/RHSA-2026:22423
- https://access.redhat.com/errata/RHSA-2026:23345