Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.23.0CPE matchmatch criteria | cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Thrift: TSSLTransportFactory.java hostname verification
May 7, 2026Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
May 5, 2026CVE-2026-43869: Apache Thrift: TSSLTransportFactory.java hostname verification
May 4, 2026