#574·usql

CVE-2026-41602 security vulnerability

Author: TortenschmeisserCreated May 12, 2026Updated May 12, 2026

github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation

Target: usr/local/bin/usql_static

Type: gobinary

Fixed version: 0.23.0

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.