https://seclists.org/oss-sec/2026/q3/265: CVE-2026-48586: Apache Thrift: TZlibTransport Decompssion Size Limit
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48586?
CVE-2026-48586 is categorized as a high-severity vulnerability in Apache Thrift.
2
How do I fix CVE-2026-48586?
To fix CVE-2026-48586, upgrade Apache Thrift to version 0.24.0 or later.
3
Which versions are affected by CVE-2026-48586?
CVE-2026-48586 affects Apache Thrift versions before 0.24.0.
4
What component of Apache Thrift is impacted by CVE-2026-48586?
CVE-2026-48586 impacts the TZlibTransport decompression functionality in Apache Thrift.
5
When was CVE-2026-48586 published?
CVE-2026-48586 was published on July 24, 2026.