CVE-2026-41603
Apache Software Foundation Apache Thrift, Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.5
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
- CVSS
- 7.4
- EPSS
- 0.57% 43.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.28