Apache disclosed three vulnerabilities in Apache Thrift affecting releases prior to 0.23.0, including CVE-2026-41607, an important-severity C++ JSON out-of-bounds read; CVE-2026-41604, a moderate-severity Swift Range crash caused by an out-of-bounds read in skip(); and CVE-2026-41636, an uncontrolled recursion issue in the Node.js implementation of skip(). The issues were published through the oss-sec mailing list in notices from Jens Geyer.
Apache said the flaws are fixed in version 0.23.0 and urged users to upgrade. The disclosures credit Hasnain Lakhani with finding the C++ and Swift issues, while 박시온 of L3G4CY Security Research was credited with the Node.js recursion bug, highlighting that the affected code spans multiple language bindings and parsers within the Thrift framework.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On April 28, 2026, Apache disclosed CVE-2026-41605, an important-severity integer overflow or wraparound vulnerability in the Swift Compact Protocol affecting Apache Thrift versions prior to 0.23.0. Apache advised users to upgrade to version 0.23.0 and credited Hasnain Lakhani with reporting the flaw.
On April 28, 2026, Apache disclosed CVE-2025-48431, an important-severity mismatched memory management vulnerability in Apache Thrift's c_glib language bindings affecting versions before 0.23.0. Apache said specially crafted requests can crash a c_glib-based Thrift server with a "free(): invalid pointer" error and advised users to upgrade to version 0.23.0.
On April 28, 2026, Apache disclosed CVE-2026-41604, a moderate-severity out-of-bounds read vulnerability described as a Swift Range crash in the skip() function affecting Apache Thrift versions prior to 0.23.0. Apache recommended upgrading to version 0.23.0; the vulnerability was credited to Hasnain Lakhani.
On April 27, 2026, Apache disclosed CVE-2026-41607, an important-severity out-of-bounds read vulnerability in Apache Thrift's C++ JSON handling affecting versions before 0.23.0. Apache recommended upgrading to version 0.23.0, and credited Hasnain Lakhani with finding the flaw.
On April 27, 2026, Apache disclosed CVE-2026-41636, an uncontrolled recursion vulnerability in the Node.js bindings' skip() functionality affecting Apache Thrift versions prior to 0.23.0. Apache advised users to upgrade to version 0.23.0; the issue was credited to 박시온 of L3G4CY Security Research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.