What is CVE-2026-49158?
CVE-2026-49158 is an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in the Apache Thrift Ruby bindings. This issue may allow data amplification attacks. Users are recommended to upgrade to Apache Thrift version 0.24.0 to fix the issue.
Azərbaycanca: CVE-2026-49158, Apache Thrift-in Ruby bağlamalarında yüksək sıxılmış verilənlərin düzgün idarə edilməməsi zəifliyidir. Bu, Data Amplification tipli hücumlara səbəb ola bilər. İstifadəçilərə problemi həll etmək üçün Apache Thrift-i 0.24.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Apache
FAQ2
What product is affected by CVE-2026-49158?
CVE-2026-49158 affects the Ruby bindings of Apache Thrift.
What is recommended to fix this Data Amplification vulnerability?
Upgrading to Apache Thrift version 0.24.0 is recommended to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.