Echo: thrift: security update to 0.19.0-4+e3

critical Tenable Self-Hosted Container Security Plugin ID 472899

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both
libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the
accessManager property does so in D — which compares the peer certificate against the host name that was
connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate
Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a
certificate whose subjectAltName entries are all present and all non-matching falls through to the Common
Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the
Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying
subjectAltName entries for one name and a Common Name for another is therefore accepted for a connection
to the second name. Exploitation requires an attacker positioned on the network path who holds a
certificate that chains to a certificate authority in the client's trust store and whose Common Name
matches the connected host name. Public certificate authorities have not issued on Common Name alone for
many years, so this is principally a concern for deployments using a private or enterprise public-key
infrastructure. This issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D
library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0. (CVE-2026-85088)

Solution

Update the thrift library and its related packages to version 0.19.0-4+e3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-85088

Plugin Details

Severity: Critical

ID: 472899

Version: Revision 1.2

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.45

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-85088

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.1

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/3/2026

Vulnerability Publication Date: 10/2/2026

Reference Information

CVE: CVE-2026-85088