Serial Number: AV26-749
Date: July 28, 2026
As of July 27, 2026, Apache is affected by vulnerabilities in the following product:
- Apache Thrift
- Prior to 0.24.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
- CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
- CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
- CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path