PT-2026-35699 · Apache · Apache Thrift

·

CVE-2026-41602

·

Published

2026-04-28

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.23.0
Description An integer overflow or wraparound issue exists in the Go language implementation of the TFramedTransport component in Apache Thrift. An integer overflow occurs when an arithmetic operation attempts to create a numeric value that is outside of the range that can be represented with a given number of digits.
Recommendations Upgrade to version 0.23.0.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85017
AZL-85220
AZL-85223
AZL-85226
AZL-85229
AZL-85292
BIT-THRIFT-2026-41602
CLEANSTART-2026-AR38431
CLEANSTART-2026-AV21509
CLEANSTART-2026-CN27900
CLEANSTART-2026-FD47409
CLEANSTART-2026-FJ76096
CLEANSTART-2026-GA28186
CLEANSTART-2026-KJ73757
CLEANSTART-2026-MA24172
CLEANSTART-2026-MC76610
CLEANSTART-2026-MJ26242
CLEANSTART-2026-PD78752
CLEANSTART-2026-RJ71322
CLEANSTART-2026-SP73148
CLEANSTART-2026-SV92564
CLEANSTART-2026-UV44486
CLEANSTART-2026-VT65447
CLEANSTART-2026-YG71543
CLEANSTART-2026-ZF00349
CVE-2026-41602
ECHO-A7C1-E4E5-DAD5
GHSA-WF45-Q9CH-Q8GH
OPENSUSE-SU-2026:10685-1
OPENSUSE-SU-2026:10692-1
OPENSUSE-SU-2026:10699-1
OPENSUSE-SU-2026:10744-1
OPENSUSE-SU-2026:20816-1
OPENSUSE-SU-2026:20940-1
SUSE-SU-2026:21852-1
SUSE-SU-2026:2243-1
SUSE-SU-2026:2258-1
SUSE-SU-2026:2438-1
SUSE-SU-2026:2768-1
SUSE-SU-2026:2774-1
SUSE-SU-2026:3056-1
SUSE-SU-2026:3057-1

Affected Products

Apache Thrift