CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompssion Bomb
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Apache Thrift
CVE-2026-49158 is classified as a critical vulnerability due to its potential to cause denial-of-service through resource exhaustion.
To fix CVE-2026-49158, update Apache Thrift to the latest version that includes the patched ZLIB decompression functionality.
CVE-2026-49158 affects systems using the Ruby implementation of Apache Thrift with ZLIB compression enabled.
Yes, CVE-2026-49158 can be exploited remotely, allowing attackers to send specially crafted data to the affected application.
The potential impacts of CVE-2026-49158 include service disruption and resource exhaustion, leading to denial-of-service conditions.