SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-48144

CRITICAL · CVSS 9.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Apache Thrift versions prior to 0.24.0 are vulnerable to a critical flaw that allows for improper validation of certificates due to host mismatches, potentially enabling attackers to perform man-in-the-middle attacks. Organizations utilizing affected versions should prioritize upgrading to 0.24.0 to mitigate the risk of unauthorized access and data interception. This vulnerability is particularly critical for systems relying on secure communications within distributed applications.

CVE
CVE-2026-48144
Severity
CRITICAL
CVSS
9.1
EPSS
0.25%
Apache

Original NVD Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)