[
https://issues.apache.org/jira/browse/HBASE-30372?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HBASE-30372:
-----------------------------------
Labels: pull-request-available (was: )
> Update Thrift to 0.24.0
> -----------------------
>
> Key: HBASE-30372
> URL: https://issues.apache.org/jira/browse/HBASE-30372
> Project: HBase
> Issue Type: Task
> Components: security, thirdparty
> Reporter: Dávid Paksy
> Assignee: Dávid Paksy
> Priority: Major
> Labels: pull-request-available
>
> Due to CVE-2026-48586 - 8.7 HIGH
> Improper Handling of Highly Compressed Data (Data Amplification)
> vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.
> This issue affects Apache Thrift: before 0.24.0. Users are recommended to
> upgrade to version 0.24.0, which fixes the issue.
> [https://nvd.nist.gov/vuln/detail/cve-2026-48586]
>
> Also there is cve-2026-45112 (6.9) medium
> Allocation of Resources Without Limits or Throttling vulnerability in Apache
> Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before
> 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the
> issue.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)