Junglewise Threat Intelligence

CVE-2026-48144: Apache Thrift improper certificate validation in c_glib bindings

CVE-2026-48144 · Severity: info · CVSS 9.1 · Published 2026-07-27

Vendors: Apache Software Foundation.

Executive brief

Apache Thrift, a framework for cross-language software development, contains a security flaw in its C (glib) library. The software fails to verify that a security certificate matches the server it is connecting to, which could allow an attacker to intercept or modify sensitive data during transmission. Organizations using these specific C bindings should update to version 0.24.0 to ensure secure communications.

Technical details

A vulnerability exists in the Apache Thrift c_glib bindings where the TLS client fails to perform proper hostname verification (CWE-297). This occurs when the library validates a certificate but does not ensure the certificate's common name or subject alternative name matches the intended host. An attacker positioned on the network (Man-in-the-Middle) could present a valid certificate for a different domain to intercept or alter encrypted traffic. The issue is resolved in Apache Thrift version 0.24.0.

Affected products

  • Apache Software Foundation Thrift before 0.24.0

Timeline

  • 2026-07-24: disclosed: Initial disclosure on oss-security mailing list
  • 2026-07-27: advisory: NVD publication date

References