CVE-2026-41602
Apache Software Foundation Apache Thrift, Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.5
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
- CVSS
- 7.5
- EPSS
- 1.16% 64.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.28