CVE-2026-66053
MEDIUMDescription
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603
Is your site exposed to CVE-2026-66053?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apache | thrift |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2026-66053? +
How severe is CVE-2026-66053? +
What products are affected by CVE-2026-66053? +
How do I check if I'm vulnerable to CVE-2026-66053? +
Related Vulnerabilities
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a …
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior …
Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured …
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check …
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package …
Allow attackers to intercept or falsify data exchanges between the client and the server