CVE-2026-41604 Details
Description
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
A out-of-bounds read vulnerability has been identified in Apache Thrift versions prior to 0.23.0. This vulnerability can lead to a crash in the Swift range handling by causing a read operation to access memory outside the intended bounds.
Users are advised to upgrade to Apache Thrift version 0.23.0 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:14885 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:21769 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22347 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22423 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23345 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:24539 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:36882 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-41604 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2463416 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41604.json | redhat-SADP | |
| http://www.openwall.com/lists/oss-security/2026/04/28/5 | CVE | Mailing List |
| https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql | [email protected] | Mailing ListPatchRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | redhat-SADP |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache thrift | < 0.23.0 |
CPE
Remediation
| |
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | CVE |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 20, 2026 | CVE Modified | redhat-SADP |
| Aug 18, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Aug 13, 2026 | CVE Modified | redhat-SADP |
| Aug 10, 2026 | CVE Modified | redhat-SADP |
| Aug 5, 2026 | CVE Modified | redhat-SADP |
| Aug 4, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Jul 28, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 23, 2026 | CVE Modified | redhat-SADP |
| Jul 22, 2026 | CVE Modified | redhat-SADP |
| Jul 21, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 9, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 28, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |
| Apr 28, 2026 | CVE Modified | CVE |