
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41605 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Apache Thrift, specifically affecting the Swift Compact Protocol implementation. It affects all versions of Apache Thrift before 0.23.0 and was publicly disclosed on April 28, 2026, by Jens Geyer via the oss-security mailing list, with credit to finder Hasnain Lakhani. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Openwall).
The vulnerability is rooted in improper handling of integer arithmetic in Apache Thrift's Swift Compact Protocol implementation, classified as CWE-190 (Integer Overflow or Wraparound). When an integer value is incremented beyond the maximum representable value for its type, it wraps around to a very small or negative number, causing the application to operate on unexpected values. The flaw is remotely exploitable with no authentication or user interaction required (network-accessible attack vector, low complexity), making it particularly dangerous in environments where Thrift services are exposed to untrusted networks (Openwall, GitHub Advisory).
Successful exploitation could result in unexpected program behavior, potential memory corruption, or denial of service against applications using the vulnerable Apache Thrift library. Depending on how the vulnerable code is utilized within a given application, attackers may also be able to achieve arbitrary code execution. The vulnerability affects confidentiality, integrity, and availability equally at a low-to-moderate level, and any service built on Apache Thrift versions prior to 0.23.0 that processes Compact Protocol messages from untrusted sources is at risk (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.018% (0.000180), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection support is available via Nessus plugin 310840 (Tenable).
Apache has released version 0.23.0 of Apache Thrift, which resolves this vulnerability. All users are strongly recommended to upgrade immediately. No configuration-based workarounds have been published; upgrading to 0.23.0 or later is the only confirmed remediation. Organizations should audit their software inventory for dependencies on Apache Thrift versions prior to 0.23.0, including transitive dependencies in downstream applications (Openwall, GitHub Advisory). Red Hat has also issued a security advisory (RHSA-2026:14885) and openSUSE has published security announcements addressing this vulnerability (Red Hat, openSUSE).
The vulnerability was announced by Apache Thrift maintainer Jens Geyer on the oss-security mailing list and the Apache announcements list, crediting Hasnain Lakhani as the finder (Openwall, Apache Announce). Downstream vendors including Red Hat and openSUSE have issued advisories and package updates in response. Social media activity has been limited to automated CVE notification accounts (Bluesky).
Fix availability across major Linux distributions and their releases.
devel
thrift
focal (esm-apps)
thrift
jammy
thrift
jammy (esm-apps)
thrift
noble
thrift
noble (esm-apps)
thrift
resolute
thrift
resolute (esm-apps)
thrift
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."