CVE-2026-41605

CVE-2026-41605: Apache Thrift: Swift Compact Protocol integer overflow

Vendor Apache Software Foundation
Product Apache Thrift
Weakness CWE-190
Published April 28, 2026
Last update April 28, 2026

CVSS base score

What the vulnerability does

Description

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Key dates

Disclosure timeline

April 28, 2026 CVE published
April 28, 2026 Record updated