VYPR
High severity7.5NVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026

CVE-2026-48586

CVE-2026-48586

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Affected products

5

Patches

Vulnerability mechanics

References

3

News mentions

2