Impact
A flaw in the Apache Thrift C++ and D libraries causes the client to fall back to the certificate Common Name when subjectAltName entries are present but do not match the host name. The fallback allows a certificate whose SAN dNSName entries are all non‑matching to be accepted if its Common Name matches the target host, thereby violating RFC 6125 and RFC 9525. An attacker could exploit this to present a fraudulent certificate that satisfies the host check and gain an authenticated TLS session to the target system.
Affected Systems
Apache Software Foundation’s Apache Thrift C++ library versions 0.7.0 through 0.24.0 and the D library versions 0.9.0 through 0.24.0 are affected. Users of these versions should install 0.25.0 or later.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in a moderate severity range. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must be positioned on the network path, posses a certificate chain that resolves to a CA in the client’s trust store, and use a Common Name that matches the intended host, making the vulnerability primarily relevant for deployments that rely on a private or enterprise public‑key infrastructure. If such conditions exist, the attacker could tunnel through the encrypted connection as though she were the legitimate server.
OpenCVE Enrichment