Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66053

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in Apache Thrift Python bindings. This vulnerability, stemming from improper validation of certificates with host mismatch, could allow a remote attacker to intercept and access sensitive information. The issue occurs when the Python client fails to adequately verify the server's certificate against its hostname, potentially enabling a man-in-the-middle (MITM) attack and leading to information disclosure.

Отчет

Moderate: This flaw in Apache Thrift Python bindings could lead to information disclosure due to improper certificate validation, allowing a remote attacker with high attack complexity to intercept sensitive data without requiring user interaction or privileges. While Red Hat Enterprise Linux AI is not affected, OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are impacted where these bindings are used in network communication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3thriftNot affected
Red Hat OpenShift Container Platform 4conmon-rsFix deferred
Red Hat OpenShift Container Platform 4kata-containersFix deferred
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2507445thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation

EPSS

Процентиль: 23%
0.00305
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

CVSS3: 5.9
nvd
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

CVSS3: 5.9
debian
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in ...

CVSS3: 5.9
github
5 дней назад

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

EPSS

Процентиль: 23%
0.00305
Низкий

5.9 Medium

CVSS3