Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48586

Опубликовано: 27 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*
Версия до 0.24.0 (исключая)

EPSS

Процентиль: 62%
0.01074
Низкий

7.5 High

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
redhat
10 дней назад

A flaw was found in Apache Thrift. This vulnerability, categorized as improper handling of highly compressed data (also known as data amplification), allows a remote attacker to cause a Denial of Service (DoS) by sending specially crafted, highly compressed data. The affected component fails to properly manage the expansion of this data, leading to resource exhaustion and system unavailability.

CVSS3: 7.5
debian
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulne ...

CVSS3: 7.5
github
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 62%
0.01074
Низкий

7.5 High

CVSS3

Дефекты

CWE-409