Junglewise Threat Intelligence

CVE-2026-49158: Apache Thrift Ruby bindings data amplification in THeaderTransport

CVE-2026-49158 · Severity: high · CVSS 7.5 · Published 2026-07-27

Vendors: Apache Software Foundation.

Executive brief

Apache Thrift is a framework used for cross-language software development and communication between different services. A vulnerability in the Ruby version of this tool allows an attacker to send specially crafted, highly compressed data (often called a 'decompression bomb') that expands to an enormous size when processed. This can exhaust the server's memory or CPU resources, leading to a complete service outage or system crash.

Technical details

A vulnerability exists in the Apache Thrift Ruby bindings due to improper handling of highly compressed data within the THeaderTransport ZLIB decompression logic. An unauthenticated remote attacker can exploit this by sending a malicious payload that triggers a 'decompression bomb' (CWE-409), causing excessive resource consumption (CPU and memory). This results in a denial of service (DoS) condition for applications utilizing the affected Ruby bindings. The issue is resolved in version 0.24.0 by implementing better safeguards against data amplification during decompression.

Affected products

  • Apache Software Foundation Thrift (Ruby bindings) < 0.24.0

Timeline

  • 2026-07-24: disclosed: Initial disclosure on oss-security mailing list
  • 2026-07-27: advisory: NVD publication date

References