Junglewise Threat Intelligence

CVE-2026-41607: Apache Thrift out-of-bounds read in C++ JSON implementation

CVE-2026-41607 · Severity: medium · CVSS 6.5 · Published 2026-04-28

Technologies: Red Hat OpenShift Container Platform, Red Hat Multicluster Global Hub, Apache Thrift. Vendors: Red Hat, Apache.

Executive brief

Apache Thrift, a framework for scalable cross-language services development, is vulnerable to a memory handling flaw. An attacker can exploit this to read sensitive information from the system's memory or cause the service to crash, leading to a denial of service. This affects various enterprise products that integrate Thrift, including Red Hat OpenShift and Advanced Cluster Management.

Technical details

An out-of-bounds (OOB) read vulnerability exists in Apache Thrift's C++ JSON protocol implementation. The flaw occurs when the library processes specially crafted input, failing to properly validate memory access boundaries. A remote, unauthenticated attacker can exploit this via the network to access memory outside of allocated buffers. This can result in the disclosure of sensitive information or trigger a crash (Denial of Service). The issue is resolved in Apache Thrift version 0.23.0. Red Hat has also issued several security advisories (e.g., RHSA-2026:14885) for downstream products incorporating the vulnerable library.

Affected products

  • Apache Thrift before 0.23.0
  • Red Hat Multicluster Global Hub 1.3.4, 1.4.5, 1.5.4, 1.6.2
  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • Red Hat OpenShift distributed tracing 3.9.3
  • Red Hat Enterprise Linux AI (RHEL AI) 3
  • Red Hat OpenShift Container Platform 4

Timeline

  • 2026-04-27: disclosed: Initial disclosure on oss-security mailing list
  • 2026-04-28: advisory: NVD publication date
  • 2026-05-07: patched: Red Hat released security advisory RHSA-2026:14885

References

Related threats