CVE-2026-41608
published 2026-07-27CVE-2026-41608: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.58%
45.8th percentile
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | >= 0 < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
ghsa·2026-07-27
CVE-2026-41608 [HIGH] CWE-409 Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
GHSA
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-41608 [HIGH] CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x zlib Decompression privilege escalation
vuldb·2026-07-26
CVE-2026-41608 [LOW] Apache Thrift up to 0.23.x zlib Decompression privilege escalation
A vulnerability identified as problematic has been detected in Apache Thrift up to 0.23.x. Affected by this issue is some unknown functionality of the component zlib Decompression Handler. This manipulation causes privilege escalation.
The identification of this vulnerability is CVE-2026-41608. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
Red Hat
thrift: Apache Thrift Python bindings: Denial of Service via data amplification
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-41608 [HIGH] CWE-409 thrift: Apache Thrift Python bindings: Denial of Service via data amplification
thrift: Apache Thrift Python bindings: Denial of Service via data amplification
A flaw was found in Apache Thrift Python bindings. This vulnerability involves the improper handling of highly compressed data, leading to a data amplification issue. An attacker could exploit this by providing specially crafted compressed input, which may cause the application to consume excessive resources. This could potentially result in a denial of service (DoS) for affected systems.
Statement: This Important vulnerability in Apache Thrift Python bindings can lead to a Denial of Service due to improper handling of highly compressed data, causing data amplification. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected wh
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [epel-all]
bugzilla·2026-08-06·CVSS 7.5
CVE-2026-41608 [HIGH] CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [epel-all]
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-41608 [HIGH] CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [fedora-all]
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-41608 [HIGH] CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification
CVE-2026-41608 thrift: Apache Thrift Python bindings: Denial of Service via data amplification
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published