CVE-2026-41603
published 2026-04-28CVE-2026-41603: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to…
PriorityP339high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
ghsa_unreviewed·2026-07-27·CVSS 5.9
CVE-2026-66053 [MEDIUM] CWE-297 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
GHSA
GHSA-gf47-qgg5-9g9q: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41603 [HIGH] CWE-297 GHSA-gf47-qgg5-9g9q: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
VulDB
Apache Thrift up to 0.22.0 Java TSSLTransportFactory certificate host validation
vuldb·2026-04-28
CVE-2026-41603 [LOW] Apache Thrift up to 0.22.0 Java TSSLTransportFactory certificate host validation
A vulnerability labeled as critical has been found in Apache Thrift up to 0.22.0. Affected is the function TSSLTransportFactory of the component Java. Executing a manipulation can lead to certificate with host mismatch.
This vulnerability appears as CVE-2026-41603. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
Red Hat
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
vendor_redhat·2026-04-28·CVSS 8.2
CVE-2026-41603 [HIGH] CWE-295 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
A flaw was found in Apache Thrift. This vulnerability involves improper validation of server certificates, where the hostname presented in the certificate does not match the expected hostname. A remote attacker could exploit this to impersonate a legitimate server, potentially intercepting or altering sensitive communications and leading to unauthorized access or information disclosure.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - A
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
bugzilla·2026-08-06·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
bugzilla·2026-08-06·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
bugzilla·2026-07-27·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Bugzilla
CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
bugzilla·2026-04-30
CVE-2026-41603 [HIGH] CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
bugzilla·2026-04-28
CVE-2026-41603 [HIGH] CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/7https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41603https://bugzilla.redhat.com/show_bug.cgi?id=2463411https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41603.json
2026-04-28
Published