top of page
perceptive_background_267k.jpg

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users a…

Published:

27 July 2026 at 00:00:00

Alert date:

27 July 2026 at 22:03:54

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Network Infrastructure

CVE-2026-48144 is an Improper Validation of Certificate with Host Mismatch vulnerability affecting Apache Thrift's c_glib bindings. The flaw allows potential man-in-the-middle attacks due to improper TLS certificate hostname validation. All versions of Apache Thrift prior to 0.24.0 are affected. The vulnerability is classified as high severity. Users are strongly recommended to upgrade to Apache Thrift version 0.24.0, which contains the fix. The issue was publicly disclosed via Apache mailing lists and the OpenWall security list. No active exploitation has been mentioned, but the nature of the vulnerability poses significant risk in environments relying on secure TLS communications.

Technical details

Mitigation steps:

Affected products:

Apache Thrift c_glib bindings (before 0.24.0)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page