CVE-2026-48145 | Apache Thrift up to 0.23.x C++ TSSLSocket matchName access control

SecurityVulns

A vulnerability described as critical has been identified in Apache Thrift up to 0.23.x. This issue affects the function matchName of the component C++ TSSLSocket. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as CVE-2026-48145. The attack is only possible within the local network. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More