Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<div>
<div>
<div><p><strong>Serial Number: </strong>AV26-749<br /><strong>Date: </strong>July 28, 2026</p>
As of July 27, 2026, Apache is affected by vulnerabilities in the following product:
- Apache Thrift
- Prior to 0.24.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
- CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
- CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
- CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
</div>
Article Link: Apache security advisory (AV26-749) - Canadian Centre for Cyber Security