CVE-2026-41602
Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update
Description
A flaw was found in the Apache Thrift TFramedTransport Go language implementation. This integer overflow or wraparound vulnerability could potentially allow an attacker to cause unexpected behavior or resource exhaustion, leading to a denial of service.
Metrics
Weakness classes (CWE)
CWE-190Base
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-09 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/41xxx/CVE-2026-41602.json">CVE-2026-41602</a>
- CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/41xxx/CVE-2026-41602.json">CVE-2026-41602</a>
- CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24) → Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24)
- CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.8, Multicluster Global Hub 1.6.2 (+24) → Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.5.6, Multicluster Global Hub 1.7.0 (+24)
- CVE Modified2026-08-20 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.6.2, Multicluster Global Hub 1.7.2 (+24) → Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.8, Multicluster Global Hub 1.6.2 (+24)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
thrift0.23.0
bitnami
golang1.26.0-0
bitnami
grafana-pyroscope1.16.0
go
github.com/gomarkdown/markdown
go
github.com/moby/moby
go
github.com/moby/moby/v2
go
golang.org/x/image
grafana
tempo1.3.0 – 2.8.4
grafana
tempo2.10.0 – 2.10.2
grafana
tempo2.9.0 – 2.9.2
jackc
pgx5.9.0
jackc
pgx
openfga
openfga0.1.4 – 1.14.0
References & sources
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2advisory
- https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38fix
- https://docs.docker.com/engine/extend/plugins_authorizationweb
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fqweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-34040advisory
- https://github.com/moby/mobypackage
- https://github.com/moby/moby/releases/tag/docker-v29.3.1web
- https://pkg.go.dev/vuln/GO-2026-4772
- https://access.redhat.com/security/cve/CVE-2026-33816vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2455972issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:41019vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:17789vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36796vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19137vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26636vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22423vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24503vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24539vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25273vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-43869
A flaw was found in Apache Thrift.
highCVSSv3 7.3 - CVE-2026-40890
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML.
highCVSSv3 7.5 - CVE-2026-40293
A flaw was found in OpenFGA, an authorization/permission engine.
mediumCVSSv3 6.5 - CVE-2026-34040
A flaw was found in Moby, an open-source container framework.
highCVSSv3 8.8 - CVE-2026-33816
A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go.
criticalCVSSv3 9.8 - CVE-2026-33815
A flaw was found in github.com/jackc/pgx.
criticalCVSSv3 9.8 - CVE-2026-33813
A flaw was found in golang.org/x/image.
highCVSSv3 7.5 - CVE-2026-32282
A flaw was found in the internal/syscall/unix package in the Go standard library.
mediumCVSSv3 6.4 - CVE-2026-32281
A flaw was found in Go's `crypto/x509` package.
highCVSSv3 7.5 - CVE-2026-21728
A flaw was found in Tempo.
highCVSSv3 7.5 - CVE-2025-41118
Pyroscope is an open-source continuous profiling database.
criticalCVSSv3 9.1