Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-85088

CVE-2026-85088: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityMedium6.9

    Medium [CVE-2026-85088] Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift

    CVE-2026-85088Source published Source updated

    Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is…

    Affected products in this advisory
    • Apache Thrift
    Source-reported affected versions
    • 0.7.0 through 0.24.0
    • 0.9.0 through 0.24.0.
    Source-reported fixed versions
    • 0.25.0
    Mitigation guidance
    • Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to.
    • Users should upgrade to 0.25.0.

Red Hat

1 advisory
  • Advisory severityHigh7.4

    High [CVE-2026-85088] Man-in-the-middle attacks via improper certificate validation

    CVE-2026-85088Source published Source updated

    Man-in-the-middle attacks via improper certificate validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:74369 with package thrift-main-0.25.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 1 more.

    Related products — impact not confirmed
    • Red Hat Hardened Images
    • Red Hat Ceph Storage 7
    • Red Hat Ceph Storage 8
    • Red Hat Ceph Storage 9

    1 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • thrift-main-0.25.0-0.1.hum1
    • RHSA-2026:74369
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery