Improper validation of certificate with host mismatch in Apache Thrift - CVE-2026-66053
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname verification in TLS certificate validation.
The vulnerability exists due to improper validation of certificate with host mismatch in the Python TSSLSocket hostname matcher import in Apache Thrift Python bindings when establishing TLS connections. A remote attacker can present a certificate with a mismatched hostname to bypass hostname verification in TLS certificate validation.
Affected software
IBM InfoSphere Information Server
InfoSphere Optim Archive Viewer
IBM Security QRadar Network Threat Analytics
Anolis OS
python3-thrift
thrift
thrift-devel
thrift-glib
thrift-qt
perl-thrift
How to mitigate CVE-2026-66053
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
InfoSphere Optim Archive Viewer - update to 11.7.0.15
python3-thrift - update to 0.24.0-1
thrift - update to 0.24.0-1
thrift-devel - update to 0.24.0-1
thrift-glib - update to 0.24.0-1
thrift-qt - update to 0.24.0-1
perl-thrift - update to 0.24.0-1
IBM Security QRadar Network Threat Analytics - update to 2.0.2