Description
Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.



Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host

name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than

a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check.



RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a

Common Name for another is therefore accepted for a connection to the second name.



Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host

name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure.



This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Improper TLS hostname verification leading to possible man‑in‑the‑middle
Action: Patch
AI Analysis

Impact

A flaw in the Apache Thrift C++ and D libraries causes the client to fall back to the certificate Common Name when subjectAltName entries are present but do not match the host name. The fallback allows a certificate whose SAN dNSName entries are all non‑matching to be accepted if its Common Name matches the target host, thereby violating RFC 6125 and RFC 9525. An attacker could exploit this to present a fraudulent certificate that satisfies the host check and gain an authenticated TLS session to the target system.

Affected Systems

Apache Software Foundation’s Apache Thrift C++ library versions 0.7.0 through 0.24.0 and the D library versions 0.9.0 through 0.24.0 are affected. Users of these versions should install 0.25.0 or later.

Risk and Exploitability

The CVSS score of 6.9 places the vulnerability in a moderate severity range. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must be positioned on the network path, posses a certificate chain that resolves to a CA in the client’s trust store, and use a Common Name that matches the intended host, making the vulnerability primarily relevant for deployments that rely on a private or enterprise public‑key infrastructure. If such conditions exist, the attacker could tunnel through the encrypted connection as though she were the legitimate server.

Generated by OpenCVE AI on October 2, 2026 at 13:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade your Apache Thrift C++ and D libraries to version 0.25.0 or later, which removes the fallback to the Common Name.
  • If an immediate upgrade is not possible, review your client trust store and remove any CA certificates that could issue certificates with a mismatched Common Name, or otherwise configure your environment to reject such certificates.
  • Audit the host name used in your Thrift client connections to ensure it always matches the subjectAltName entries of the server certificate; if autofail on mismatch is not available, consider manually verifying the certificate chain during connection establishment.

Generated by OpenCVE AI on October 2, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a Common Name for another is therefore accepted for a connection to the second name. Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host name. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure. This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.
Title Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match
Weaknesses CWE-295
CWE-297
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T11:37:14.749Z

Reserved: 2026-09-02T23:36:14.032Z

Link: CVE-2026-85088

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:21.800

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-85088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:16Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-297

    Improper Validation of Certificate with Host Mismatch