CVE-2026-43869

CVE-2026-43869: Apache Thrift: TSSLTransportFactory.java hostname verification

Vendor Apache Software Foundation
Product Apache Thrift
Weakness CWE-297
Published May 5, 2026
Last update May 6, 2026

CVSS base score

What the vulnerability does

Description

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Key dates

Disclosure timeline

May 5, 2026 CVE published
May 6, 2026 Record updated