PatchDay Alert

CVE

CVE-2026-43869

0field notes · 1digest CVSS 7.3


Daily digests

Apache Thrift's TSSLTransportFactory in Java doesn't properly verify hostnames during TLS connections. An attacker in a network position to intercept traffic (think man-in-the-middle) could impersonate a Thrift service endpoint without triggering a certificate error. This only matters if your Java services use Thrift's built-in TLS transport.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.