CVE-2026-48586·Python vulnerability
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
- Severity
- high
- Software
- Python
- Fixed in
- 0.24.0
- Published
- 2026-07-27
Affected versions
Until: 0.24.0
Fixed in: 0.24.0
How to fix this CVE
Python environments using Apache Thrift are vulnerable to a denial-of-service attack when processing compressed data payloads. Upgrade Python's Apache Thrift bindings to version 0.24.0 or later to eliminate the data amplification vulnerability. Organizations should prioritize this update for systems handling untrusted Thrift-serialized data from network sources.
sudo dnf update python3-thriftDefensia detects this vulnerability
How to check if you are affected
- Run 'python3 -c "import thrift; print(thrift.__version__)"' to determine the installed Thrift version; any version below 0.24.0 is vulnerable.
- Execute 'pip3 show thrift' to check if the Python Thrift package is installed via pip and confirm its version number.
- Review application logs for sudden memory spikes or process crashes correlating with incoming Thrift RPC calls, which may indicate compression bomb attempts.
- After patching, re-run the version check commands to confirm Thrift has been updated to 0.24.0 or higher.
FAQ
What is CVE-2026-48586?
This vulnerability affects Apache Thrift's handling of highly compressed data across multiple language bindings, including Python. Attackers can send specially crafted compressed payloads that expand to consume excessive memory or CPU resources, causing denial of service.
Is CVE-2026-48586 being actively exploited?
No, CVE-2026-48586 is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept exploits are available. However, the high CVSS score warrants prompt remediation.
What versions of Python are affected by CVE-2026-48586?
All Python versions using Apache Thrift versions prior to 0.24.0 are affected. The vulnerability exists in the Thrift library bindings, not in Python itself.
How do I check if my server is vulnerable to CVE-2026-48586?
Run 'pip3 show thrift' or 'python3 -c "import thrift; print(thrift.__version__)"' to check the installed Thrift version; if it is below 0.24.0, your server is vulnerable.
Does Defensia detect CVE-2026-48586?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Python Thrift is installed on a monitored server, CVE-2026-48586 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-48586. Free for 1 server.
Get started free