PT-2026-64881 · Apache · Apache Thrift

CVE-2026-48145

·

Published

2026-07-27

·

Updated

2026-08-01

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description Improper validation of certificates with host mismatch occurs in the Apache Thrift C++ bindings. This issue involves a wildcard bypass in the matchName() function of the TSSLSocket class, failing to adhere to RFC 6125 standards.
Recommendations Upgrade to version 0.24.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94004
BIT-THRIFT-2026-48145
CVE-2026-48145
ECHO-DE98-1A44-0C2E
OPENSUSE-SU-2026:11432-1

Affected Products

Apache Thrift