Skip to main content

Improper Validation of Certificate with Host Mismatch

CVE-2026-43869

Severity High
Score 7.3/10

Summary

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift prior to 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • LOW

CWE-297 - Improper Validation of Certificate with Host Mismatch

The software communicates with a host that provides a certificate, but the software does not properly ensure that the certificate is actually associated with that host.

Advisory Timeline

  • Published