PT-2026-64893 · Apache · Apache Thrift

CVE-2026-66053

·

Published

2026-07-27

·

Updated

2026-09-10

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Thrift versions prior to 0.24.0
Description Apache Thrift Python bindings contain an issue where certificates with host mismatches are not properly validated.
Recommendations Upgrade to version 0.24.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93980
BIT-THRIFT-2026-66053
CVE-2026-66053
GHSA-HWRJ-9RR4-24XH
PYSEC-2026-3927

Affected Products

Apache Thrift