MEDIUM5.9
GHSA-hwrj-9rr4-24xh
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Quick fix
GHSA-hwrj-9rr4-24xh — thrift: upgrade to the fixed version with the command below.
pip install --upgrade 'thrift>=0.24.0'Details
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Are you affected?
Enter the version of the package you're using.