Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41608

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

A flaw was found in Apache Thrift Python bindings. This vulnerability involves the improper handling of highly compressed data, leading to a data amplification issue. An attacker could exploit this by providing specially crafted compressed input, which may cause the application to consume excessive resources. This could potentially result in a denial of service (DoS) for affected systems.

Отчет

This Important vulnerability in Apache Thrift Python bindings can lead to a Denial of Service due to improper handling of highly compressed data, causing data amplification. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected when processing untrusted input via these bindings, potentially exhausting system resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3thriftNot affected
Red Hat OpenShift Container Platform 4conmon-rsNot affected
Red Hat OpenShift Container Platform 4kata-containersNot affected
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2507442thrift: Apache Thrift Python bindings: Denial of Service via data amplification

EPSS

Процентиль: 62%
0.01097
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
14 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
14 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
msrc
4 дня назад

Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport

CVSS3: 7.5
debian
14 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulne ...

CVSS3: 7.5
github
14 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 62%
0.01097
Низкий

7.5 High

CVSS3