CVE-2026-48144
Apache Thrift’s c_glib bindings had a flaw that let attackers trick the system into accepting a certificate that didn’t match the host. This could let a malicious server impersonate a legitimate one. The issue is fixed in Thrift 0.24.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Thrift c_glib bindings, any version earlier than 0.24.0, used by developers building applications that rely on Thrift communication.
Real-world impact
An attacker could pose as a trusted server, intercept or modify data, and potentially gain full control over the application’s communication channel.
Why this severity
The CVSS score of 9.1 reflects the high impact on confidentiality and integrity, combined with a moderate exploitation difficulty. The vulnerability allows attackers to bypass certificate validation, making it a critical risk.
What to do about it
- 01Upgrade Apache Thrift to version 0.24.0 or later.
- 02Restart any services or applications that use Thrift after the upgrade.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.apache.org/thread/2xoltfxgzf5jyhcwq6y0…vendor advisory
- lists.apache.org/thread/7v3jhgwfbmhx42424phy…release notes
- openwall.com/lists/oss-security/2026/07/…mailing listthird party advisory