A vulnerability classified as problematic was found in Apache Thrift up to 0.22.0. This vulnerability affects unknown code of the component C++ JSON Handler. Such manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as CVE-2026-41607. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.