Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25060

Опубликовано: 02 фев. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify setting is default to true in the DefaultConfig() function in internal/conf/config.go. This vulnerability enables Man-in-the-Middle (MitM) attacks by disabling TLS certificate verification, allowing attackers to intercept and manipulate all storage communications. Attackers can exploit this through network-level attacks like ARP spoofing, rogue Wi-Fi access points, or compromised internal network equipment to redirect traffic to malicious endpoints. Since certificate validation is skipped, the system will unknowingly establish encrypted connections with attacker-controlled servers, enabling full decryption, data theft, and manipulation of all storage operations without triggering any security warnings. This vulnerability is fixed in 4.1.10.

EPSS

Процентиль: 1%
0.00008
Низкий

8.1 High

CVSS3

Дефекты

CWE-599

Связанные уязвимости

CVSS3: 8.1
github
5 дней назад

OpenList has Insecure TLS Default Configuration

EPSS

Процентиль: 1%
0.00008
Низкий

8.1 High

CVSS3

Дефекты

CWE-599