Dávid Paksy created HBASE-30372:
-----------------------------------
Summary: Update Thrift to 0.24.0
Key: HBASE-30372
URL: https://issues.apache.org/jira/browse/HBASE-30372
Project: HBase
Issue Type: Task
Components: security, thirdparty
Reporter: Dávid Paksy
Due to CVE-2026-48586
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects
Apache Thrift: before 0.24.0. Users are recommended to upgrade to version
0.24.0, which fixes the issue.
[https://nvd.nist.gov/vuln/detail/cve-2026-48586]
--
This message was sent by Atlassian Jira
(v8.20.10#820010)