CVE-2026-48586
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
Published:
7/27/2026
Last updated:
7/27/2026
Reserved:
5/21/2026
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
CNA assigner:
apache (f0158376-9dc2-43b6-827c-5f631a4d8d09)
Requested by:
n/a
Opam packages affected (1)
thrift