Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwrj-9rr4-24xh

Опубликовано: 27 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

EPSS

Процентиль: 23%
0.00305
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-297

Связанные уязвимости

CVSS3: 5.9
ubuntu
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

CVSS3: 5.9
redhat
5 дней назад

A flaw was found in Apache Thrift Python bindings. This vulnerability, stemming from improper validation of certificates with host mismatch, could allow a remote attacker to intercept and access sensitive information. The issue occurs when the Python client fails to adequately verify the server's certificate against its hostname, potentially enabling a man-in-the-middle (MITM) attack and leading to information disclosure.

CVSS3: 5.9
nvd
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

CVSS3: 5.9
debian
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in ...

EPSS

Процентиль: 23%
0.00305
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-297