CVE-2026-41603
published 2026-04-28CVE-2026-41603: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to…
PriorityP346high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.57%
43.4th percentile
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf47-qgg5-9g9q: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
ghsa_unreviewed·2026-04-28
CVE-2026-41603 [HIGH] CWE-297 GHSA-gf47-qgg5-9g9q: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
VulDB
Apache Thrift up to 0.22.0 Java TSSLTransportFactory certificate host validation
vuldb·2026-04-28
CVE-2026-41603 [LOW] Apache Thrift up to 0.22.0 Java TSSLTransportFactory certificate host validation
A vulnerability labeled as critical has been found in Apache Thrift up to 0.22.0. Affected is the function TSSLTransportFactory of the component Java. Executing a manipulation can lead to certificate with host mismatch.
This vulnerability appears as CVE-2026-41603. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
Red Hat
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
vendor_redhat·2026-04-28·CVSS 8.2
CVE-2026-41603 [HIGH] CWE-295 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
A flaw was found in Apache Thrift. This vulnerability involves improper validation of server certificates, where the hostname presented in the certificate does not match the expected hostname. A remote attacker could exploit this to impersonate a legitimate server, potentially intercepting or altering sensitive communications and leading to unauthorized access or information disclosure.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - A
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
bugzilla·2026-04-30
CVE-2026-41603 [HIGH] CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
CVE-2026-41603 golang-github-apache-thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
bugzilla·2026-04-28
CVE-2026-41603 [HIGH] CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
CVE-2026-41603 Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/7https://access.redhat.com/errata/RHSA-2026:14885https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2026-41603https://bugzilla.redhat.com/show_bug.cgi?id=2463411https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41603.json
2026-04-28
Published