CVE-2026-43869: CWE-297 Improper Validation of Certificate with Host Mismatch in Apache Software Foundation Apache Thrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
AI Analysis
Technical Summary
Apache Thrift versions before 0.23.0 suffer from a security bypass vulnerability due to improper validation of certificates when the certificate's host does not match the expected host. This weakness (CWE-297 and CWE-295) allows an attacker to present a malicious certificate that the software incorrectly accepts, enabling impersonation of trusted entities. The vulnerability affects the integrity and confidentiality of communications by potentially allowing unauthorized access or data disclosure. The issue is fixed in Apache Thrift 0.23.0. Red Hat's advisory confirms the vulnerability and provides updates for affected products, including Cryostat 4 on RHEL 9, with the fix included in recent security updates.
Potential Impact
The vulnerability allows remote attackers to bypass certificate validation checks, potentially impersonating legitimate servers or clients. This can lead to unauthorized access or information disclosure. The impact is rated as low confidentiality, low integrity, and low availability impact, but the overall severity is high due to the potential for security bypass without requiring user interaction or privileges.
Mitigation Recommendations
An official fix is available in Apache Thrift version 0.23.0. Users are strongly recommended to upgrade to this version or later to remediate the vulnerability. Red Hat has released security updates including this fix for affected products such as Cryostat 4 on RHEL 9. No alternative mitigations meeting Red Hat's criteria are currently available. Users should apply the vendor-provided updates as soon as possible.
CVE-2026-43869: CWE-297 Improper Validation of Certificate with Host Mismatch in Apache Software Foundation Apache Thrift
Description
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVSS v3.1
Score 7.3high
Affected software
Apache Software Foundation
Apache Thrift
pkg:maven/org.apache.thrift/libthriftRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Thrift versions before 0.23.0 suffer from a security bypass vulnerability due to improper validation of certificates when the certificate's host does not match the expected host. This weakness (CWE-297 and CWE-295) allows an attacker to present a malicious certificate that the software incorrectly accepts, enabling impersonation of trusted entities. The vulnerability affects the integrity and confidentiality of communications by potentially allowing unauthorized access or data disclosure. The issue is fixed in Apache Thrift 0.23.0. Red Hat's advisory confirms the vulnerability and provides updates for affected products, including Cryostat 4 on RHEL 9, with the fix included in recent security updates.
Potential Impact
The vulnerability allows remote attackers to bypass certificate validation checks, potentially impersonating legitimate servers or clients. This can lead to unauthorized access or information disclosure. The impact is rated as low confidentiality, low integrity, and low availability impact, but the overall severity is high due to the potential for security bypass without requiring user interaction or privileges.
Mitigation Recommendations
An official fix is available in Apache Thrift version 0.23.0. Users are strongly recommended to upgrade to this version or later to remediate the vulnerability. Red Hat has released security updates including this fix for affected products such as Cryostat 4 on RHEL 9. No alternative mitigations meeting Red Hat's criteria are currently available. Users should apply the vendor-provided updates as soon as possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-05-04T14:22:44.030Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-43869","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28010","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22423","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22347","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21769","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23345","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24503","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30651","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24539","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25273","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26586","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27126","vendor":"Red Hat"}]
Threat ID: 69f9a181cbff5d8610d825a6
Added to database: 05/05/2026, 07:51:29 UTC
Last enriched: 08/13/2026, 14:04:48 UTC
Last updated: 09/17/2026, 22:01:35 UTC
Views: 242
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.