Improper validation of certificate with host mismatch in Apache Thrift - CVE-2026-66053
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname verification in TLS certificate validation.
The vulnerability exists due to improper validation of certificate with host mismatch in the Python TSSLSocket hostname matcher import in Apache Thrift Python bindings when establishing TLS connections. A remote attacker can present a certificate with a mismatched hostname to bypass hostname verification in TLS certificate validation.
Affected software
Anolis OS
python3-thrift
thrift
thrift-devel
thrift-glib
thrift-qt
perl-thrift
How to mitigate CVE-2026-66053
python3-thrift - update to 0.24.0-1
thrift - update to 0.24.0-1
thrift-devel - update to 0.24.0-1
thrift-glib - update to 0.24.0-1
thrift-qt - update to 0.24.0-1
perl-thrift - update to 0.24.0-1