REDHAT-BUG-2463416: High severity Apache Apache Thrift vulnerability
Published Apr 28, 2026
·Updated
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected Software
1 affected component
Apache Apache Thrift<0.23.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.23.0
Event History
Apr 28, 2026
Data Sourced
via Red Hat·10:02 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2463416?
The severity of REDHAT-BUG-2463416 is high, rated at 7.
2
How do I fix REDHAT-BUG-2463416?
To fix REDHAT-BUG-2463416, upgrade Apache Thrift to version 0.23.0 or later.
3
What type of vulnerability is REDHAT-BUG-2463416?
REDHAT-BUG-2463416 is classified as an out-of-bounds read vulnerability.
4
Which versions of Apache Thrift are affected by REDHAT-BUG-2463416?
Apache Thrift versions prior to 0.23.0 are affected by REDHAT-BUG-2463416.
5
When was REDHAT-BUG-2463416 published?
REDHAT-BUG-2463416 was published on April 28, 2026.