MEDIUM5.9
PYSEC-2026-3927
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Quick fix
PYSEC-2026-3927 — thrift: upgrade to the fixed version with the command below.
pip install --upgrade 'thrift>=0.24.0'Details
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
This replaces CVE-2026-41603
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-66053[ADVISORY]
- https://github.com/apache/thrift[PACKAGE]
- https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9[WEB]
- https://lists.apache.org/thread/w4k5dnv1x58knwlhpo9x0or5xh220y65[WEB]
- https://pypi.org/project/thrift[PACKAGE]
- https://github.com/advisories/GHSA-hwrj-9rr4-24xh[ADVISORY]