Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49158

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Apache Thrift Ruby bindings. This vulnerability, categorized as improper handling of highly compressed data, allows a remote attacker to cause a denial of service (DoS) through a data amplification attack. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users.

Отчет

This Important vulnerability in Apache Thrift Ruby bindings could allow a remote, unauthenticated attacker to trigger a denial of service. By sending specially crafted compressed data, an attacker can cause excessive resource consumption, leading to service unavailability in affected Red Hat products that utilize these bindings, such as OpenShift Container Platform components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3thriftNot affected
Red Hat OpenShift Container Platform 4conmon-rsNot affected
Red Hat OpenShift Container Platform 4kata-containersAffected
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2507435thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
debian
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulne ...

CVSS3: 7.5
github
10 дней назад

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

7.5 High

CVSS3