Apache security advisory (AV26-749)
Serial Number: AV26-749 Date: July 28, 2026 As of July 27, 2026, Apache is affected by vulnerabilities in the following product: Apache Thrift Prior to 0.24.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
CSIRTS triage
- What
- Apache Thrift has multiple vulnerabilities related to decompression and integer overflow.
- Who is affected
- Users of Apache Thrift prior to version 0.24.0 are affected.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to various issues, although exploitation status is currently unknown.
- Action
- Users should update to Apache Thrift version 0.24.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Thrift
Get an email when a new Thrift advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av26-749
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-485861.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
- Moderate exploitation riskCVE-2026-491581.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
- Moderate exploitation riskCVE-2026-559691.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
- Moderate exploitation riskCVE-2026-580231.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48586 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49158 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55969 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58023 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalCVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache T…nvd
- highCVE-2026-55969: Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi …nvd
- highCVE-2026-49158: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrif…nvd
- highCVE-2026-48586: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrif…nvd
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30