CVE-2026-41606

CVE-2026-41606: Apache Thrift: c_glib dispatch stack overflow

Vendor Apache Software Foundation
Product Apache Thrift
Weakness CWE-674
Published April 28, 2026
Last update April 28, 2026

CVSS base score

What the vulnerability does

Description

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Key dates

Disclosure timeline

April 28, 2026 CVE published
April 28, 2026 Record updated