
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48586 is a data amplification vulnerability ("zip bomb" / decompression bomb) in Apache Thrift's TZlibTransport component, classified as CWE-409 (Improper Handling of Highly Compressed Data). It affects the C++, Java, Python, Go, D, and C/GLib language bindings of Apache Thrift in all versions before 0.24.0. The vulnerability was disclosed by Apache on July 24, 2026, with NVD publication on July 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Apache OSS-Security, Apache Advisory).
The root cause is improper handling of highly compressed data (CWE-409) within Apache Thrift's TZlibTransport layer, which performs zlib-based decompression without enforcing adequate size limits on the decompressed output. An unauthenticated remote attacker can craft a small, highly compressed payload (a "decompression bomb") that expands to a disproportionately large amount of data upon decompression, causing excessive CPU and memory consumption on the server. No authentication, user interaction, or special privileges are required to trigger the condition — any network-accessible Thrift service using TZlibTransport is potentially vulnerable. The specific component identified in the advisory is TZlibTransport Decompression Size Limit (Apache OSS-Security).
Successful exploitation results in a denial-of-service condition through resource exhaustion (CPU and/or memory), with no impact on confidentiality or integrity. Because the vulnerability affects multiple language bindings (C++, Java, Python, Go, D, C/GLib), any service built on Apache Thrift using compressed transport is potentially affected, broadening the attack surface across heterogeneous environments. The NVD assessment classifies the technical impact as partial and the attack as automatable, meaning an attacker could script repeated requests to sustain or amplify the denial-of-service effect (Apache OSS-Security, Apache Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.0107 (~1.07%), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is network-based, requires no authentication, and is considered automatable, which lowers the barrier for potential future exploitation (Apache Advisory).
TZlibTransport (compressed transport), which is identifiable by Thrift protocol negotiation behavior.TZlibTransport decompresses the payload without enforcing output size limits, consuming excessive memory and/or CPU, leading to service degradation or crash (denial of service).TZlibTransport; Java heap space errors or native memory allocation failures in Java-based Thrift services.The primary remediation is to upgrade Apache Thrift to version 0.24.0 or later, which enforces decompression size limits in TZlibTransport (Apache OSS-Security, Apache Advisory). Red Hat has issued security errata (RHSA-2026:46931, RHSA-2026:46974, RHSA-2026:46987) for affected packages. As interim workarounds, organizations should implement network-level controls to restrict the maximum size of compressed payloads accepted from untrusted sources, apply rate limiting on Thrift endpoints, and restrict access to Thrift services to trusted network segments where possible.
Red Hat issued multiple security advisories (RHSA-2026:46931, RHSA-2026:46974, RHSA-2026:46987) addressing the vulnerability in their product lines. The Canadian Centre for Cyber Security (CCCS) published advisory AV26-749 covering the Apache Thrift issue. openSUSE also issued a security announcement for affected packages. Community discussion has been limited, with automated security feeds and aggregators (VulnDB, Vulners, CVEFeed) picking up the disclosure shortly after publication. No significant researcher commentary or social media debate has been observed beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."