<Vulnerability name="CVE-2026-49158">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-27T11:05:07</PublicDate>
    <Bugzilla id="2507435" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507435" xml:lang="en:us">
thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-409</CWE>
    <Details xml:lang="en:us" source="Mitre">
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache Thrift Ruby bindings. This vulnerability, categorized as improper handling of highly compressed data, allows a remote attacker to cause a denial of service (DoS) through a data amplification attack. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users.
    </Details>
    <Statement xml:lang="en:us">
This Important vulnerability in Apache Thrift Ruby bindings could allow a remote, unauthenticated attacker to trigger a denial of service. By sending specially crafted compressed data, an attacker can cause excessive resource consumption, leading to service unavailability in affected Red Hat products that utilize these bindings, such as OpenShift Container Platform components.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState impact="important" cpe="cpe:/a:redhat:confidential_compute_attestation:1">
        <ProductName>Confidential Compute Attestation</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-sandboxed-containers/osc-podvm-payload-rhel9</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>thrift</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>conmon-rs</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>kata-containers</PackageName>
    </PackageState>
    <PackageState impact="important" cpe="cpe:/a:redhat:openshift_update_service:5">
        <ProductName>Red Hat OpenShift Update Service</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-update-service/openshift-update-service-rhel8</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-49158
https://nvd.nist.gov/vuln/detail/CVE-2026-49158
http://www.openwall.com/lists/oss-security/2026/07/24/38
https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7
    </References>
</Vulnerability>