https://seclists.org/oss-sec/2026/q3/260: CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompssion in Python THeaderTransport
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
The severity of CVE-2026-41608 is classified as important.
CVE-2026-41608 affects Apache Thrift versions before 0.24.0.
To fix CVE-2026-41608, users should upgrade to Apache Thrift version 0.24.0 or later.
CVE-2026-41608 is an improper handling of highly compressed data vulnerability.
CVE-2026-41608 can lead to data amplification attacks that may negatively impact performance and security.