Jens Geyer created THRIFT-6083:
----------------------------------

             Summary: Add decompressed payload size limit to Python 
THeaderTransport
                 Key: THRIFT-6083
                 URL: https://issues.apache.org/jira/browse/THRIFT-6083
             Project: Thrift
          Issue Type: Bug
          Components: Python - Library
            Reporter: Jens Geyer
             Fix For: 0.24.0


THeaderTransport._parse_header_format() applied ZLIB decompression via a bare 
zlib.decompress(payload) call with no upper bound on the decompressed output 
size. The existing frame-size check constrained only the compressed wire data.

Fixed by decompressing through {{zlib.decompressobj().decompress(payload, 
max_length)}} with a configurable {{_max_decompressed_size}} (default: 
DEFAULT_MAX_FRAME_SIZE) and a {{set_max_decompressed_size()}} setter, raising 
{{TTransportException(SIZE_LIMIT)}} when exceeded.

*Affects:* Python
*Fixed by:* branch {{python-zlib-limit}}, merged via PR #3408 (2026-04-19); 
fixed in 0.24.0

*CWE-409:* Improper Handling of Highly Compressed Data (Data Amplification)
*CVSS 3.1:* 7.5 High ({{CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H}})

*Reported by:* an external researcher via [email protected] (signed "K")
*CVE:* CVE-2026-41608



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to