REDHAT-BUG-2466660: High severity Apache Thrift vulnerability
Published May 5, 2026
·Updated
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected Software
1 affected component
Apache Thrift<0.23.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.23.0
Event History
May 5, 2026
Data Sourced
via Red Hat·08:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2466660?
The severity of REDHAT-BUG-2466660 is high, rated at 7.
2
How do I fix REDHAT-BUG-2466660?
To fix REDHAT-BUG-2466660, users should upgrade to Apache Thrift version 0.23.0 or later.
3
What is the impact of REDHAT-BUG-2466660?
REDHAT-BUG-2466660 can lead to improper validation of certificates, potentially allowing host mismatch vulnerabilities.
4
Which versions of Apache Thrift are affected by REDHAT-BUG-2466660?
Apache Thrift versions prior to 0.23.0 are affected by REDHAT-BUG-2466660.
5
When was REDHAT-BUG-2466660 published?
REDHAT-BUG-2466660 was published on May 5, 2026.