CVE-2026-85087
MEDIUM
6,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
295
Improper Certificate Validation
DraftCommon Consequences
Security Scopes Affected:
Integrity
Authentication
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Mobile
393
Return of Wrong Status Code
DraftCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Unexpected State
Alter Execution Logic
Applicable Platforms
All platforms may be affected
https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1
https://lists.apache.org/thread/l2rgp3dqhpy2w347forzdt9g7o2d6k0d