Apache Thrift Improper Certificate Validation Vulnerability Allowing Host Mismatch

Vulnerability

A vulnerability exists in Apache Thrift versions prior to 0.23.0, allowing improper validation of certificates, particularly in scenarios where there is a host mismatch. This flaw could potentially be exploited in contexts where secure communication is established using SSL/TLS.

Impact

Exploitation of this vulnerability could lead to improper validation of SSL/TLS certificates, allowing for man-in-the-middle attacks or other forms of interception in secure communications.

Remediation

Users are advised to upgrade to Apache Thrift version 0.23.0 or later, which addresses this vulnerability.

Added: Apr 28, 2026, 10:38 AM
Updated: Apr 28, 2026, 10:38 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
5.0
exploitability
7.0
remediation
7.7
relevance
6.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.