CVE-2026-41604

CVE-2026-41604: Apache Thrift: Swift Range crash in skip()

Vendor Apache Software Foundation
Product Apache Thrift
Weakness CWE-125
Published April 28, 2026
Last update April 28, 2026

CVSS base score

What the vulnerability does

Description

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Key dates

Disclosure timeline

April 28, 2026 CVE published
April 28, 2026 Record updated