CVE-2026-48145
published 2026-07-27CVE-2026-48145: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.27%
19.4th percentile
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache | thrift | — | — |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
ghsa_unreviewed·2026-07-27
CVE-2026-48145 [HIGH] CWE-297 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
VulDB
Apache Thrift up to 0.23.x C++ TSSLSocket matchName access control
vuldb·2026-07-26
CVE-2026-48145 [CRITICAL] Apache Thrift up to 0.23.x C++ TSSLSocket matchName access control
A vulnerability described as critical has been identified in Apache Thrift up to 0.23.x. This issue affects the function matchName of the component C++ TSSLSocket. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-48145. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.
Red Hat
apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
vendor_redhat·2026-07-27·CVSS 7.5
CVE-2026-48145 [HIGH] CWE-297 apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift C++ bindings. This vulnerability, caused by improper validation of certificates with host mismatch, could allow a remote attacker to disclose sensitive information.
Statement: This vulnerability strictly impacts Confidentiality with zero effect on Integrity or Availability (C:H, I:N, A:N). Exploitation allows a remote attacker to conduct a man-in-the-middle (MitM) attack and intercept sensitive data transmitted over TLS if hostname validation f
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [epel-all]
bugzilla·2026-08-07·CVSS 7.5
CVE-2026-48145 [HIGH] CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [epel-all]
CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [fedora-all]
bugzilla·2026-08-07·CVSS 7.5
CVE-2026-48145 [HIGH] CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [fedora-all]
CVE-2026-48145 thrift: Apache Thrift: Information disclosure due to improper certificate validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Bugzilla
CVE-2026-48145 apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-48145 [HIGH] CVE-2026-48145 apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
CVE-2026-48145 apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
2026-07-27
Published