Apache · Apache Thrift · CVE-2026-49158
**Name of the Vulnerable Software and Affected Versions**
Apache Thrift versions prior to 0.24.0
**Description**
Improper handling of highly compressed data, known as data amplification, exists in the Apache Thrift Ruby bindings. This issue occurs during ZLIB decompression within the `THeaderTransport` component, which could lead to a decompression bomb, where a small compressed input expands to a massive size in memory.
**Recommendations**
Upgrade to version 0.24.0.