CVE-2026-85086: Apache Thrift: Perl TLS client disables certificate verification by default
Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift Perl bindingsto a version that resolves this vulnerability.Fixed in 0.25.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the Apache Thrift Perl bindings with versions before 0.25.0 are affected. The issue specifically concerns TLS client certificate verification.
Is the insecure behavior enabled by default?
Yes. The Perl TLS client initializes certificate verification with an insecure default, disabling certificate verification by default.
What should be done to remediate the issue?
Upgrade Apache Thrift to version 0.25.0, which fixes the issue.