Apache Thrift <0.25.0: Improper Handling of Compressed Data in Python Bindings
CVE-2026-94636 Published on October 2, 2026

Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Vendor Advisory Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-94636 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Types

What is a Data Amplification Vulnerability?

The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.

CVE-2026-94636 has been classified to as a Data Amplification vulnerability or weakness.

Function Call with Incorrectly Specified Arguments

The product calls a function, procedure, or routine with arguments that are not correctly specified, leading to always-incorrect behavior and resultant weaknesses.

Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.


Products Associated with CVE-2026-94636

Want to know whenever a new CVE is published for Apache Thrift? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Thrift: