CVE-2026-48586: Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
Other sources
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.24.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-28 - Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.24.0Patch CVE-2026-48586
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48586?
The severity of CVE-2026-48586 is classified as medium, indicating a potential risk of resource exhaustion.
How do I fix CVE-2026-48586?
To fix CVE-2026-48586, update to the latest version of Apache Thrift that addresses the decompression size limit vulnerability.
What is the impact of CVE-2026-48586?
CVE-2026-48586 can lead to denial-of-service conditions by exhausting resources through excessive decompression attempts.
Which versions of Apache Thrift are affected by CVE-2026-48586?
CVE-2026-48586 affects certain versions of Apache Thrift prior to the patch that handles decompression size limits.
Is CVE-2026-48586 easy to exploit?
CVE-2026-48586 may be exploited with relatively low complexity, particularly if the attacker has control over the input data.