CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-41608

highCVSS 7.5covered by 2 sourcesfirst seen 2026-07-27
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CSIRTS triage

What
Unbounded Zlib decompression in Python THeaderTransport allows memory exhaustion attack.
Who is affected
Python applications using Apache Thrift THeaderTransport.
Urgency
High priority; CVSS 7.5 and denial of service impact.
Action
Apply Apache Thrift patch or upgrade to patched Python version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-41608

Get an email if CVE-2026-41608 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-41608

CVE.org record

Embed the live status

CVE-2026-41608 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-41608 status](https://www.csirts.com/badge/CVE-2026-41608)](https://www.csirts.com/cve/CVE-2026-41608)