Improper validation of certificate with host mismatch in Apache Thrift - CVE-2026-48145
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname verification.
The vulnerability exists due to improper validation of certificate with host mismatch in the C++ TSSLSocket matchName() function when validating wildcard certificate names during TLS certificate verification. A remote attacker can present a crafted certificate with a mismatched hostname to bypass hostname verification.
Affected software
Anolis OS
python3-thrift
thrift
thrift-devel
thrift-glib
thrift-qt
perl-thrift
How to mitigate CVE-2026-48145
python3-thrift - update to 0.24.0-1
thrift - update to 0.24.0-1
thrift-devel - update to 0.24.0-1
thrift-glib - update to 0.24.0-1
thrift-qt - update to 0.24.0-1
perl-thrift - update to 0.24.0-1