
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-94637 is a data amplification (zip bomb / decompression bomb) vulnerability in the Apache Thrift Go bindings, classified under CWE-409 (Improper Handling of Highly Compressed Data). It affects all versions of Apache Thrift before 0.25.0 and was publicly disclosed on October 2, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is improper handling of highly compressed input data (CWE-409) within the Apache Thrift Go language bindings. When a Thrift service processes compressed messages, it fails to impose adequate limits on decompression output size, allowing a small, specially crafted compressed payload to expand into a disproportionately large amount of data — a classic "decompression bomb" or data amplification attack. Exploitation requires no authentication and no user interaction; an attacker only needs network access to a Thrift service endpoint that accepts compressed data, and the attack requirements note that specific deployment conditions (AT:P) must be present for the amplification to be triggered (GitHub Advisory, Red Hat Bugzilla). No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation causes excessive CPU and memory consumption on the affected Thrift service during decompression, leading to service degradation or a complete crash — a denial-of-service condition. There is no impact on confidentiality or data integrity; the vulnerability is purely an availability issue. Services built on the Apache Thrift Go bindings and exposed to untrusted network traffic are at risk, and a sustained attack could render dependent microservices or APIs unavailable (GitHub Advisory, Red Hat Bugzilla).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the disclosure date (Feedly). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The CVE status is listed as "Deferred" and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is unauthenticated and network-accessible, but requires specific deployment conditions (compressed data processing enabled) to be exploitable.
TZlibTransport or similar compressed transport layer in Go bindings)./var/log/syslog, journalctl) recording OOM killer events targeting the Thrift service process.The primary remediation is to upgrade the Apache Thrift Go bindings to version 0.25.0 or later, which addresses the improper decompression handling (GitHub Advisory). As interim workarounds, operators should implement network-level rate limiting on Thrift service endpoints to reduce the impact of amplification attempts, and restrict Thrift service access to trusted networks or authenticated clients where architecturally feasible. Resource monitoring and alerting on CPU/memory thresholds for Thrift service processes can help detect and respond to exploitation attempts before full service failure occurs (Feedly).
The vulnerability was disclosed via the Apache mailing list and tracked by Red Hat's Product Security team, which opened a high-severity bug report and added 59 users to the CC list, indicating broad internal concern across Red Hat products that may depend on Apache Thrift Go bindings (Red Hat Bugzilla). No notable independent researcher commentary or significant social media discussion has been identified at this time.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."