CVE-2026-41608

CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport

Vendor Apache Software Foundation
Product Apache Thrift
Weakness CWE-409
Published July 27, 2026
Last update July 28, 2026

CVSS base score

What the vulnerability does

01Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Key dates

02Disclosure timeline

July 27, 2026 CVE published
July 28, 2026 Record updated