Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85088— Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match

Quick assessment

Affected
Apache Software Foundation Apache Thrift
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Thrift C++ 和 D 语言库中存在证书与主机名不匹配时的验证不当漏洞。 这两个库分别为客户端套接字安装了默认的访问管理器:C++ 库使用 ,D 库则通过 属性实现。这些管理器会将对等方的证书与已连接的主机名进行比较。该比较过程首先检查 (主题备用名称)中的 条目,若未匹配,再进一步检查证书的 (通用名称)。然而,当主机名不匹配时,系统仅返回“跳过”(skip)结果,而非拒绝连接。因此,如果证书的所有 条目均存在但与目标主机名不匹配,验证过程会继续检查 ,而该 可能满足匹配条件,从而导致验证错误

CVSS 6.9 · Medium EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache Thrift < 0.25.0 affected
< 0.25.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a Common Name for another is therefore accepted for a connection to the second name. Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure. This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Thrift 0 ~ 0.25.0 -
Apache Software Foundation Apache Thrift 0 ~ 0.25.0 -

II. Public POCs for CVE-2026-85088

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85088

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-85088 (2)

Same Patch Batch · Apache Software Foundation · 2026-10-02 · 69 CVEs total

CVE-2026-102795 9.3 CRITICAL Apache Traffic Server: SNI to Host header matching policy is not properly enforced
CVE-2026-91135 9.2 CRITICAL Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction)
CVE-2026-83632 9.2 CRITICAL Apache Thrift: C++ THttpTransport grows its line buffer without bound
CVE-2026-61373 8.7 HIGH Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation
CVE-2026-66859 8.7 HIGH Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
CVE-2026-94658 8.7 HIGH Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (
CVE-2026-94646 8.7 HIGH Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two tri
CVE-2026-87117 8.7 HIGH Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element
CVE-2026-86535 8.7 HIGH Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely
CVE-2026-82458 8.7 HIGH Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift,
CVE-2026-96294 8.7 HIGH Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection
CVE-2026-86537 8.7 HIGH Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthen
CVE-2026-94642 8.7 HIGH Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception
CVE-2026-85493 8.7 HIGH Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth
CVE-2026-85494 8.7 HIGH Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift,
CVE-2026-91137 8.7 HIGH Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements
CVE-2026-93925 8.7 HIGH Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative
CVE-2026-93926 8.7 HIGH Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error pa
CVE-2026-94633 8.7 HIGH Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned na
CVE-2026-94635 8.7 HIGH Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pr

Showing top 20 of 69 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-85088

No comments yet


Leave a comment