[ 
https://issues.apache.org/jira/browse/THRIFT-6088?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6088.
--------------------------------
      Assignee: Jens Geyer
    Resolution: Fixed

> Add decompressed size limit to TZlibTransport across C++, Java, Python, Go, 
> D, and C/GLib
> -----------------------------------------------------------------------------------------
>
>                 Key: THRIFT-6088
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6088
>             Project: Thrift
>          Issue Type: Bug
>          Components: C glib - Library, C++ - Library, D - Library, Go - 
> Library, Java - Library, Python - Library
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Major
>             Fix For: 0.24.0
>
>
> TZlibTransport.read() decompressed incoming data without enforcing any limit 
> on total decompressed bytes, in every language implementation that has this 
> transport. A small, highly compressed payload could expand to hundreds of 
> megabytes, exhausting server memory. Two variants of the same underlying gap 
> existed: C++ and C/GLib called checkReadBytesAvailable() but never called 
> countConsumedMessageBytes(), so the check was silently bypassed; Java, 
> Python, Go, and D performed no accounting at all. Ruby, PHP, Node.js, and 
> Rust have no TZlibTransport and are unaffected.
> Fixed per language:
> * C++ (commit 61231d62f): complete the existing check by calling 
> countConsumedMessageBytes()
> * Java (commit 709d76e92): checkReadBytesAvailable() + 
> countConsumedMessageBytes() added to read()
> * Python (commit 1c0bfbc6c): bounded decompress() via max_length, raises 
> SIZE_LIMIT on overflow
> * Go (commit d4fe304f1): bytesRead counter enforced against 
> conf.GetMaxMessageSize()
> * D (commit 05421845b): maxDecompressedSize parameter (default 100MB) + 
> bytesRead_ counter
> * C/GLib (commit 8df285e25): complete the existing check by calling 
> countConsumedMessageBytes()
> *Affects:* all versions with TZlibTransport, in C++, Java, Python, Go, D, and 
> C/GLib; fixed in 0.24.0
> *CWE-409:* Improper Handling of Highly Compressed Data (Data Amplification)
> *CVSS 4.0:* 8.7 High 
> ({{CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N}})
> *Reported by:* discovered internally (2026-05-21)
> *CVE:* CVE-2026-48586



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to