CVE-2026-66053
published 2026-07-27CVE-2026-66053: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.21%
11.6th percentile
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.24.0 | 0.24.0 |
| apache_software_foundation | apache_thrift | < 0.24.0 | 0.24.0 |
| kata-containers | kata-containers | — | — |
| openshift-sandboxed-containers | osc-podvm-payload-rhel9 | — | — |
| openshift-update-service | openshift-update-service-rhel8 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
ghsa_unreviewed·2026-07-27·CVSS 5.9
CVE-2026-66053 [MEDIUM] CWE-297 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
VulDB
Apache Thrift up to 0.23.x privilege escalation
vuldb·2026-07-26
CVE-2026-66053 [LOW] Apache Thrift up to 0.23.x privilege escalation
A vulnerability categorized as problematic has been discovered in Apache Thrift up to 0.23.x. This vulnerability affects unknown code. Such manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2026-66053. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
Red Hat
thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
vendor_redhat·2026-07-27·CVSS 5.9
CVE-2026-66053 [MEDIUM] CWE-295 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
A flaw was found in Apache Thrift Python bindings. This vulnerability, stemming from improper validation of certificates with host mismatch, could allow a remote attacker to intercept and access sensitive information. The issue occurs when the Python client fails to adequately verify the server's certificate against its hostname, potentially enabling a man-in-the-middle (MITM) attack and leading to information disclosure.
Statement: Moderate: This flaw in Apache Thrift Python bindings could lead to information disclosure due to improper certificate validation, allowing a remote attacker with high attack complexity to intercept sensitive data without requiring user interaction or privilege
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
bugzilla·2026-08-06·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
bugzilla·2026-08-06·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Bugzilla
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
bugzilla·2026-07-27·CVSS 5.9
CVE-2026-66053 [MEDIUM] CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
CVE-2026-66053 thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
2026-07-27
Published