CVE-2026-85088
CVE-2026-85088: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityMedium6.9
Medium [CVE-2026-85088] Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift
CVE-2026-85088Source published Source updated
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is…
- Affected products in this advisory
- Apache Thrift
- Source-reported affected versions
- 0.7.0 through 0.24.0
- 0.9.0 through 0.24.0.
- Source-reported fixed versions
- 0.25.0
- Mitigation guidance
- Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to.
- Users should upgrade to 0.25.0.
Red Hat
1 advisory- Advisory severityHigh7.4
High [CVE-2026-85088] Man-in-the-middle attacks via improper certificate validation
CVE-2026-85088Source published Source updated
Man-in-the-middle attacks via improper certificate validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:74369 with package thrift-main-0.25.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 1 more.
- Related products — impact not confirmed
- Red Hat Hardened Images
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
1 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- thrift-main-0.25.0-0.1.hum1
- RHSA-2026:74369
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.