StackRadar

CVE-2026-41608

High

Advisory

Published 27 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 1
affected package

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
thriftpypi0.11.0, 0.13.0, 0.15.0, 0.16.0+2 more0.24.025
OSV records
GHSA-6pjx-3pjc-mrj8
Also known as
BIT-thrift-2026-41608, PYSEC-2026-3925

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
thrift@0.16.0
0.24.0

Open the chart page →

6,543
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
thrift@0.21.0
0.24.0

Open the chart page →

5,987
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
thrift@0.13.0
0.24.0

Open the chart page →

5,851
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
thrift@0.13.0
0.24.0

Open the chart page →

52,919
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
thrift@0.16.0
0.24.0

Open the chart page →

27,267
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
thrift@0.22.0
0.24.0

Open the chart page →

5,557
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
thrift@0.22.0
0.24.0

Open the chart page →

107,811
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
thrift@0.16.0
0.24.0

Open the chart page →

12,397
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
thrift@0.13.0
0.24.0

Open the chart page →

7,129
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
thrift@0.15.0
0.24.0

Open the chart page →

3,332
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
thrift@0.11.0
0.24.0

Open the chart page →

20,671
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
thrift@0.13.0
0.24.0

Open the chart page →

22,891
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
thrift@0.11.0
0.24.0

Open the chart page →

18,980
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
thrift@0.11.0
0.24.0

Open the chart page →

5,060
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
thrift@0.16.0
0.24.0

Open the chart page →

5,062
gmaas-github-apigmaas-github-api2.0.11 of 1See more

gmaas-github-api gmaas-github-api 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
gmaas2/github-api:latest148fc2d9afe9
thrift@0.16.0
0.24.0

Open the chart page →

1,205
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
thrift@0.15.0
0.24.0

Open the chart page →

3,314
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
thrift@0.11.0
0.24.0

Open the chart page →

18,980
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
thrift@0.16.0
0.24.0

Open the chart page →

16,417
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
thrift@0.22.0
0.24.0

Open the chart page →

8,405
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
thrift@0.11.0
0.24.0

Open the chart page →

9,378
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
thrift@0.11.0
0.24.0

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
thrift@0.11.0
0.24.0

Open the chart page →

20,462
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
thrift@0.16.0
0.24.0

Open the chart page →

9,256
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
thrift@0.15.0
0.24.0

Open the chart page →

21,997
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
thrift@0.15.0
0.24.0

Open the chart page →

3,164
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
thrift@0.16.0
0.24.0

Open the chart page →

7,085
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-41608.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
thrift@0.15.0
0.24.0

Open the chart page →

22,665

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amancevice/superset:0.35.212a0a9e66550
thrift@0.13.0
0.24.0
2
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
thrift@0.11.0
0.24.0
2
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
thrift@0.11.0
0.24.0
2
amancevice/superset:0.28.1c8c04bfe3d66
thrift@0.11.0
0.24.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
thrift@0.13.0
0.24.0
1
apache/superset:4.0.1ab9467fd712c
thrift@0.16.0
0.24.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
thrift@0.22.0
0.24.0
1
datamate/seafile-professional:11.0.202dd66b722464
thrift@0.16.0
0.24.0
1
gethue/hue:4.11.011b649636e68
thrift@0.16.0
0.24.0
1
gethue/hue:4.10.05702b2c37ff9
thrift@0.13.0
0.24.0
1
gethue/hue:latest7d5c1b9f8a79
thrift@0.16.0
0.24.0
1
gmaas2/github-api:latest148fc2d9afe9
thrift@0.16.0
0.24.0
1
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
thrift@0.11.0
0.24.0
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
thrift@0.11.0
0.24.0
1
matrixdotorg/synapse:v1.160.078de1d10bef0
thrift@0.22.0
0.24.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
thrift@0.16.0
0.24.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
thrift@0.15.0
0.24.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
thrift@0.15.0
0.24.0
1
redash/redash:25.8.000d813437db5
thrift@0.21.0
0.24.0
1
redash/redash:10.0.0.b503639392753c0376
thrift@0.15.0
0.24.0
1
redash/redash:26.3.0c5c9148f5c38
thrift@0.16.0
0.24.0
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
thrift@0.15.0
0.24.0
1
temporalio/admin-tools:1.15.135034611d981
thrift@0.15.0
0.24.0
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
thrift@0.16.0
0.24.0
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
thrift@0.22.0
0.24.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.