Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48145

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

A flaw was found in Apache Thrift C++ bindings. This vulnerability, caused by improper validation of certificates with host mismatch, could allow a remote attacker to disclose sensitive information.

Отчет

This vulnerability strictly impacts Confidentiality with zero effect on Integrity or Availability (C:H, I:N, A:N). Exploitation allows a remote attacker to conduct a man-in-the-middle (MitM) attack and intercept sensitive data transmitted over TLS if hostname validation fails. Red Hat rates this flaw with High Attack Complexity (AC:H) in contrast to NVD's Low Attack Complexity because successful exploitation requires specific, non-default network positioning to intercept traffic alongside a valid TLS certificate that triggers the host mismatch condition. Applications that do not use Apache Thrift C++ bindings for SSL/TLS encrypted client connections, or those operating exclusively over trusted private networks, are unaffected.

Меры по смягчению последствий

To mitigate this issue, restrict network access to systems utilizing Apache Thrift C++ bindings for SSL/TLS encrypted client connections to trusted private networks only. If feasible, avoid using Apache Thrift C++ bindings for SSL/TLS encrypted client connections in environments where man-in-the-middle attacks are a concern.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3thriftAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=2507431apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation

EPSS

Процентиль: 36%
0.00435
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
15 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
nvd
15 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 7.5
msrc
4 дня назад

Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass

CVSS3: 7.5
debian
15 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in ...

CVSS3: 7.5
github
15 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

EPSS

Процентиль: 36%
0.00435
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2026-48145