[ 
https://issues.apache.org/jira/browse/HBASE-30372?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dávid Paksy updated HBASE-30372:
--------------------------------
    Status: Patch Available  (was: In Progress)

> Update Thrift to 0.24.0
> -----------------------
>
>                 Key: HBASE-30372
>                 URL: https://issues.apache.org/jira/browse/HBASE-30372
>             Project: HBase
>          Issue Type: Task
>          Components: security, thirdparty
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>
> Due to CVE-2026-48586 - 8.7 HIGH
> Improper Handling of Highly Compressed Data (Data Amplification) 
> vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. 
> This issue affects Apache Thrift: before 0.24.0. Users are recommended to 
> upgrade to version 0.24.0, which fixes the issue.
> [https://nvd.nist.gov/vuln/detail/cve-2026-48586]
>  
> Also there is cve-2026-45112 (6.9) medium 
> Allocation of Resources Without Limits or Throttling vulnerability in Apache 
> Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 
> 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the 
> issue.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to