CVE-2026-48586: Apache Thrift: TZlibTransport Decompssion Size Limit
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift
The severity of CVE-2026-48586 is classified as medium, indicating a potential risk of resource exhaustion.
To fix CVE-2026-48586, update to the latest version of Apache Thrift that addresses the decompression size limit vulnerability.
CVE-2026-48586 can lead to denial-of-service conditions by exhausting resources through excessive decompression attempts.
CVE-2026-48586 affects certain versions of Apache Thrift prior to the patch that handles decompression size limits.
CVE-2026-48586 may be exploited with relatively low complexity, particularly if the attacker has control over the input data.