Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

CVE-2026-85086: Apache Thrift can accept forged certificates

CVE-2026-85086 · published 8 days ago
Summary

The Perl libraries for Apache Thrift do not verify security certificates correctly and start with unsafe settings. This could let attackers pretend to be a trusted service and intercept data. Update the Apache Thrift package to version 0.25.0 or later to fix the problem.

What to do
  • Update apache software foundation apache thrift to version 0.25.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache thrift < 0.25.0
Debian:12 debian thrift All versions
Ubuntu:20.04:LTS canonical thrift All versions
Original advisory text
DEBIAN-CVE-2026-85086
Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
6.9 Medium
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published2 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Track software like this
Free during beta