Executive brief
Apache Thrift, a framework for cross-language software development, contains a security flaw in its C (glib) library. The software fails to verify that a security certificate matches the server it is connecting to, which could allow an attacker to intercept or modify sensitive data during transmission. Organizations using these specific C bindings should update to version 0.24.0 to ensure secure communications.
Technical details
A vulnerability exists in the Apache Thrift c_glib bindings where the TLS client fails to perform proper hostname verification (CWE-297). This occurs when the library validates a certificate but does not ensure the certificate's common name or subject alternative name matches the intended host. An attacker positioned on the network (Man-in-the-Middle) could present a valid certificate for a different domain to intercept or alter encrypted traffic. The issue is resolved in Apache Thrift version 0.24.0.
Affected products
- Apache Software Foundation Thrift before 0.24.0
Timeline
- 2026-07-24: disclosed: Initial disclosure on oss-security mailing list
- 2026-07-27: advisory: NVD publication date