


Perceptive Security
SOC/SIEM Consultancy

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users a…
Published:
27 July 2026 at 00:00:00
Alert date:
27 July 2026 at 22:03:54
Source:
nvd.nist.gov
Enterprise Applications, Network Infrastructure
CVE-2026-48144 is an Improper Validation of Certificate with Host Mismatch vulnerability affecting Apache Thrift's c_glib bindings. The flaw allows potential man-in-the-middle attacks due to improper TLS certificate hostname validation. All versions of Apache Thrift prior to 0.24.0 are affected. The vulnerability is classified as high severity. Users are strongly recommended to upgrade to Apache Thrift version 0.24.0, which contains the fix. The issue was publicly disclosed via Apache mailing lists and the OpenWall security list. No active exploitation has been mentioned, but the nature of the vulnerability poses significant risk in environments relying on secure TLS communications.
Technical details
Mitigation steps:
Affected products:
Apache Thrift c_glib bindings (before 0.24.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48144
https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9
http://www.openwall.com/lists/oss-security/2026/07/24/35
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
