REDHAT-BUG-2463408: High severity Apache Apache Thrift vulnerability
Published Apr 28, 2026
·Updated
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected Software
1 affected component
Apache Apache Thrift<0.23.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache/thriftto a version that resolves this vulnerability.Fixed in 0.23.0
Event History
Apr 28, 2026
Data Sourced
via Red Hat·10:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2463408?
The severity of REDHAT-BUG-2463408 is classified as high with a rating of 7.
2
What software is affected by REDHAT-BUG-2463408?
REDHAT-BUG-2463408 affects Apache Thrift versions before 0.23.0.
3
How do I fix REDHAT-BUG-2463408?
To fix REDHAT-BUG-2463408, users should upgrade to Apache Thrift version 0.23.0 or later.
4
What type of vulnerability is REDHAT-BUG-2463408?
REDHAT-BUG-2463408 is an uncontrolled recursion vulnerability.
5
When was REDHAT-BUG-2463408 published?
REDHAT-BUG-2463408 was published on April 28, 2026.