Description
Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings.



This issue affects Apache Thrift: before 0.25.0.



Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Man-in-the-Middle
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Apache Thrift’s Python bindings arises from an improper host‑name check that silently becomes a no‑op when running on Python versions 3.12 and later. This flaw allows an attacker to bypass certificate validation and potentially intercept or inject traffic to a trusted Thrift server. The weakness results in the return of an incorrect status code and opens the door to man‑in‑the‑middle attacks that compromise confidentiality and integrity of the data exchanged over the network.

Affected Systems

Apache Thrift versions prior to 0.25.0 are affected by this issue. The flaw is present in all builds utilizing the Python bindings, regardless of the platform, as the host‑name validation logic is part of the universal Thrift client implementation.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. Because the EPSS score is not available, the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV, there is no publicly documented exploitation at the time of this analysis. Attackers would need network access must trigger the client’s insecure TLS handshake. If they succeed, they could masquerade as the legitimate server and gain unauthorized access to the data flow.

Generated by OpenCVE AI on October 2, 2026 at 13:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Thrift 0.25.0 or later to resolve the host‑name validation flaw.
  • If upgrade is delayed, add explicit hostname verification in the client after TLS handshake, comparing the server’s presented certificate with the expected host name.
  • Augment network security by restricting Thrift traffic to known peers and monitor for abnormal TLS connections that could indicate a man‑in‑the‑middle attempt.

Generated by OpenCVE AI on October 2, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache thrift
Vendors & Products Apache
Apache thrift

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Title Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op
Weaknesses CWE-295
CWE-393
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:35:44.871Z

Reserved: 2026-09-02T23:32:53.894Z

Link: CVE-2026-85087

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:21.640

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-85087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-393

    Return of Wrong Status Code