This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-41603 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
This CVE ID is Rejected and will not be used. The record incorrectly described the affected language binding and fixed version. Use CVE-2026-66053, which was assigned to the vulnerability.
CVE-2026-41603 Blast Radius
✕ WITHDRAWN — HISTORICAL DATAImproper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are rec…