https://seclists.org/oss-sec/2026/q3/265: CVE-2026-48586: Apache Thrift: TZlibTransport Decompssion Size Limit
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
CVE-2026-48586 is categorized as a high-severity vulnerability in Apache Thrift.
To fix CVE-2026-48586, upgrade Apache Thrift to version 0.24.0 or later.
CVE-2026-48586 affects Apache Thrift versions before 0.24.0.
CVE-2026-48586 impacts the TZlibTransport decompression functionality in Apache Thrift.
CVE-2026-48586 was published on July 24, 2026.