CVE-2026-41605
Apache Thrift vulnerability analysis and mitigation

Overview

CVE-2026-41605 is an Integer Overflow or Wraparound vulnerability (CWE-190) in Apache Thrift, specifically affecting the Swift Compact Protocol implementation. It affects all versions of Apache Thrift before 0.23.0 and was publicly disclosed on April 28, 2026, by Jens Geyer via the oss-security mailing list, with credit to finder Hasnain Lakhani. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Openwall).

Technical details

The vulnerability is rooted in improper handling of integer arithmetic in Apache Thrift's Swift Compact Protocol implementation, classified as CWE-190 (Integer Overflow or Wraparound). When an integer value is incremented beyond the maximum representable value for its type, it wraps around to a very small or negative number, causing the application to operate on unexpected values. The flaw is remotely exploitable with no authentication or user interaction required (network-accessible attack vector, low complexity), making it particularly dangerous in environments where Thrift services are exposed to untrusted networks (Openwall, GitHub Advisory).

Impact

Successful exploitation could result in unexpected program behavior, potential memory corruption, or denial of service against applications using the vulnerable Apache Thrift library. Depending on how the vulnerable code is utilized within a given application, attackers may also be able to achieve arbitrary code execution. The vulnerability affects confidentiality, integrity, and availability equally at a low-to-moderate level, and any service built on Apache Thrift versions prior to 0.23.0 that processes Compact Protocol messages from untrusted sources is at risk (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.018% (0.000180), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection support is available via Nessus plugin 310840 (Tenable).

Mitigation and workarounds

Apache has released version 0.23.0 of Apache Thrift, which resolves this vulnerability. All users are strongly recommended to upgrade immediately. No configuration-based workarounds have been published; upgrading to 0.23.0 or later is the only confirmed remediation. Organizations should audit their software inventory for dependencies on Apache Thrift versions prior to 0.23.0, including transitive dependencies in downstream applications (Openwall, GitHub Advisory). Red Hat has also issued a security advisory (RHSA-2026:14885) and openSUSE has published security announcements addressing this vulnerability (Red Hat, openSUSE).

Community reactions

The vulnerability was announced by Apache Thrift maintainer Jens Geyer on the oss-security mailing list and the Apache announcements list, crediting Hasnain Lakhani as the finder (Openwall, Apache Announce). Downstream vendors including Red Hat and openSUSE have issued advisories and package updates in response. Social media activity has been limited to automated CVE notification accounts (Bluesky).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

thrift

Affected

sid

thrift: 0.23.0-3

Fixed

trixie

thrift

Affected

Ubuntu

Unknown

devel

thrift

Unknown

focal (esm-apps)

thrift

Unknown

jammy

thrift

Unknown

jammy (esm-apps)

thrift

Unknown

noble

thrift

Unknown

noble (esm-apps)

thrift

Unknown

resolute

thrift

Unknown

resolute (esm-apps)

thrift

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/ztp-site-generate-rhel8

Affected

Alpine

Fixed

edge

thrift: 0.23.0-r0

Fixed

SourceThis report was generated using AI

Related Apache Thrift vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55971CRITICAL9.3
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58662HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58389HIGH8.7
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-58023MEDIUM6.9
  • Apache Thrift logoApache Thrift
  • thrift
NoYesJul 27, 2026
CVE-2026-66053MEDIUM5.9
  • Python logoPython
  • thrift
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management