CVE-2026-49158
published 2026-07-27CVE-2026-49158: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.65%
48.4th percentile
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-49158 [HIGH] CWE-409 Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x THeaderTransport zlib Decompression denial of service
vuldb·2026-07-26
CVE-2026-49158 [LOW] Apache Thrift up to 0.23.x THeaderTransport zlib Decompression denial of service
A vulnerability classified as problematic was found in Apache Thrift up to 0.23.x. The affected element is an unknown function of the component THeaderTransport zlib Decompression Handler. The manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-49158. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
Red Hat
thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-49158 [HIGH] CWE-409 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
A flaw was found in Apache Thrift Ruby bindings. This vulnerability, categorized as improper handling of highly compressed data, allows a remote attacker to cause a denial of service (DoS) through a data amplification attack. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users.
Statement: This Important vulnerability in Apache Thrift Ruby bindings could allow a remote, unauthenticated attacker to trigger a denial of service. By sending specially crafted compressed data, an attacker can cause excessive resource consumption, leading to service unavailability in affected Red Hat products that util
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
bugzilla·2026-08-19·CVSS 7.5
CVE-2026-49158 [HIGH] CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-49158 kata-containers: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
bugzilla·2026-08-19·CVSS 7.5
CVE-2026-49158 [HIGH] CVE-2026-49158 kata-containers: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
CVE-2026-49158 kata-containers: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [epel-all]
bugzilla·2026-08-19·CVSS 7.5
CVE-2026-49158 [HIGH] CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [epel-all]
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-49158 [HIGH] CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
CVE-2026-49158 thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published