CVE-2026-41602

Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update

Description

A flaw was found in the Apache Thrift TFramedTransport Go language implementation. This integer overflow or wraparound vulnerability could potentially allow an attacker to cause unexpected behavior or resource exhaustion, leading to a denial of service.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
65.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-08 14:02 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-09 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/41xxx/CVE-2026-41602.json">CVE-2026-41602</a>
  2. CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/41xxx/CVE-2026-41602.json">CVE-2026-41602</a>
  3. CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24)Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24)
  4. CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.8, Multicluster Global Hub 1.6.2 (+24)Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24)
  5. CVE Modified2026-08-20 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.6.2, Multicluster Global Hub 1.7.2 (+24)Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.8, Multicluster Global Hub 1.6.2 (+24)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    thrift0.23.0

  • bitnami

    golang1.26.0-0

  • bitnami

    grafana-pyroscope1.16.0

  • go

    github.com/gomarkdown/markdown

  • go

    github.com/moby/moby

  • go

    github.com/moby/moby/v2

  • go

    golang.org/x/image

  • grafana

    tempo1.3.0 – 2.8.4

  • grafana

    tempo2.10.0 – 2.10.2

  • grafana

    tempo2.9.0 – 2.9.2

  • jackc

    pgx5.9.0

  • jackc

    pgx

  • openfga

    openfga0.1.4 – 1.14.0

References & sources

Linked CVEs

IDCVE-2026-41602