Improper Handling of Compressed Data in Apache Thrift by Apache
CVE-2026-41608

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 July 2026

What is CVE-2026-41608?

A vulnerability exists in Apache Thrift's Python bindings due to improper handling of highly compressed data, leading to potential data amplification issues. This flaw affects versions of Apache Thrift prior to 0.24.0. It is essential for users to update to version 0.24.0 or later to mitigate this risk and enhance the overall security posture of their applications.

Affected Version(s)

Apache Thrift 0 < 0.24.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.