Improper Handling of Compressed Data in Apache Thrift Ruby Bindings
CVE-2026-49158

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 July 2026

What is CVE-2026-49158?

A vulnerability exists in the Ruby bindings of Apache Thrift due to improper handling of highly compressed data, which can lead to data amplification. This can potentially be exploited, allowing for the manipulation of data processing workflows. It is crucial for users running versions prior to 0.24.0 to take corrective actions by upgrading to version 0.24.0, which addresses this vulnerability effectively.

Affected Version(s)

Apache Thrift 0 < 0.24.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LTSHFWJT <1719636402@qq.com>
.