https://seclists.org/oss-sec/2026/q3/263: CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Apache Thrift<0.24.0
CVE-2026-48144 has a severity level that indicates a high risk due to improper validation of certificate with host mismatch.
The recommended fix for CVE-2026-48144 is to upgrade to Apache Thrift version 0.24.0 or later.
CVE-2026-48144 affects all versions of Apache Thrift (glibc language bindings) before version 0.24.0.
CVE-2026-48144 can lead to man-in-the-middle attacks due to the lack of hostname verification in TLS connections.
To check if your version is vulnerable to CVE-2026-48144, verify if it is earlier than Apache Thrift version 0.24.0.