GHSA-7pwc-h2j2-rjgj

Suggest an improvement
Source
https://github.com/advisories/GHSA-7pwc-h2j2-rjgj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7pwc-h2j2-rjgj/GHSA-7pwc-h2j2-rjgj.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-7pwc-h2j2-rjgj
Aliases
Downstream
CGA (38)
MINI (6)
Published
2026-05-05T09:31:55Z
Modified
2026-07-17T21:15:30Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
Details

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-297"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-08T19:19:58Z",
    "nvd_published_at": "2026-05-05T08:16:01Z",
    "severity": "HIGH"
}
References

Affected packages

Maven / org.apache.thrift:libthrift

Package

Name
org.apache.thrift:libthrift
View open source insights on deps.dev
Purl
pkg:maven/org.apache.thrift/libthrift

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.0

Affected versions

0.*
0.6.1
0.7.0
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.3-1
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.14.2
0.15.0
0.16.0
0.17.0
0.18.0
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0

Database specific

last_known_affected_version_range
"<= 0.22.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7pwc-h2j2-rjgj/GHSA-7pwc-h2j2-rjgj.json"