SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66053

MEDIUM · CVSS 5.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Apache Thrift Python bindings prior to version 0.24.0 are vulnerable to an improper validation of certificate with host mismatch, potentially allowing attackers to exploit this flaw for man-in-the-middle attacks. Organizations utilizing affected versions should prioritize upgrading to version 0.24.0 to mitigate the risk of unauthorized access and data interception.

CVE
CVE-2026-66053
Severity
MEDIUM
CVSS
5.9
EPSS
0.21%
Apache

Original NVD Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

Related CVEs

Other vulnerabilities affecting the same vendor(s)