What is CVE-2026-48586?
CVE-2026-48586 is an improper handling of highly compressed data (Data Amplification) vulnerability in Apache Thrift's C++, Java, Python, Go, D, and C/GLib bindings. This flaw could allow an attacker to cause excessive resource consumption, potentially leading to a denial of service via specially crafted compressed payloads. Users are recommended to upgrade to version 0.24.0 to mitigate the issue.
Azərbaycanca: CVE-2026-48586, Apache Thrift-in C++, Java, Python, Go, D, C/GLib binding-lərində yüksək sıxışdırılmış məlumatların düzgün idarə olunmaması (Data Amplification) zəifliyidir. Bu boşluq, təcavüzkarlara xüsusi hazırlanmış sıxışdırılmış yüklər vasitəsilə resursları həddindən artıq istehlak edərək xidmətin dayandırılmasına səbəb ola bilər. İstifadəçilərə problemi aradan qaldıran 0.24.0 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which components of Apache Thrift are affected by CVE-2026-48586?
CVE-2026-48586 affects the C++, Java, Python, Go, D, and C/GLib bindings of Apache Thrift.
To which version should users upgrade to mitigate CVE-2026-48586?
Users are recommended to upgrade to Apache Thrift version 0.24.0 to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.