Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
CVE-2026-85086: Apache Thrift can accept forged certificates
CVE-2026-85086 · published 8 days ago
Summary
The Perl libraries for Apache Thrift do not verify security certificates correctly and start with unsafe settings. This could let attackers pretend to be a trusted service and intercept data. Update the Apache Thrift package to version 0.25.0 or later to fix the problem.
What to do
- Update apache software foundation apache thrift to version 0.25.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache thrift | < 0.25.0 |
| Debian:12 | debian | thrift | All versions |
| Ubuntu:20.04:LTS | canonical | thrift | All versions |
Original advisory text
DEBIAN-CVE-2026-85086
Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
References
- https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
- https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy
- https://security-tracker.debian.org/tracker/CVE-2026-85086 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-85086 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-85086 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
6.9
Medium
Type
CWE-295Improper Certificate Validation
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published2 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Sources
CVE-2026-85086 · NVD
CVE-2026-85086 · MITRE
DEBIAN-CVE-2026-85086 · OSV
UBUNTU-CVE-2026-85086 · OSV
Track software like this
Free during beta