Improper Handling of Highly Compressed Data in Apache Thrift by Apache
CVE-2026-48586
8.7HIGH
What is CVE-2026-48586?
A vulnerability exists in Apache Thrift due to improper handling of highly compressed data, which may lead to data amplification issues. This affects various language bindings including C++, Java, Python, Go, D, and C/GLib. Users are strongly advised to upgrade to version 0.24.0 or later to mitigate potential risks associated with this weakness.
Affected Version(s)
Apache Thrift 0 < 0.24.0
Apache Thrift 0 < 0.24.0
Apache Thrift 0 < 0.24.0