CVE-2026-41603: Apache Thrift: Java TSSLTransportFactory hostname verification
Apache Thrift: Java TSSLTransportFactory hostname verification
Other sources
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
— Red Hat
Rejected reason: This CVE ID is Rejected and will not be used. The record incorrectly described the affected language binding and fixed version. Use CVE-2026-66053, which was assigned to the vulnerability.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift (Java)to a version that resolves this vulnerability.Fixed in 0.23.0Patch CVE-2026-66053
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41603?
CVE-2026-41603 has a moderate severity rating due to its impact on hostname verification leading to potential man-in-the-middle attacks.
How do I fix CVE-2026-41603?
To fix CVE-2026-41603, upgrade Apache Thrift to version 0.23.0 or later.
What versions of Apache Thrift are affected by CVE-2026-41603?
CVE-2026-41603 affects all Apache Thrift versions prior to 0.23.0.
What kind of vulnerability is CVE-2026-41603?
CVE-2026-41603 is an improper validation vulnerability in hostname verification within the Java TSSLTransportFactory.
Can CVE-2026-41603 lead to a security breach?
Yes, CVE-2026-41603 can lead to security breaches by allowing attackers to perform man-in-the-middle attacks due to certificate validation failures.