Tag

#TLS

blogHIGH 7.5

CVE-2026-62243: Netty TLS Hostname Verification Bypass

CVE-2026-62243 is a vulnerability in Netty's OpenSSL client path that allows a man-in-the-middle attacker to present a certificate issued for a different hostname without validation. This occurs when using a plain X509TrustManager and Unsafe-based trust-manager wrapping is unavailable. The vulnerability has a CVSS score of 7.5 and is fixed in Netty versions 4.2.17.Final and 4.1.137.Final.

1 source
newsCRITICAL 9.1

Critical Vulnerability in GeoVision GV-AS1620 (GV-Cloud) Firmware

A critical vulnerability (CVE-2026-18754) with a CVSS score of 9.1 has been discovered in GeoVision GV-AS1620 (GV-Cloud) firmware, allowing malicious actors to breach the confidentiality and integrity of HTTPS communications. The vulnerability affects version V1.16 of the product. Immediate action is required to mitigate this vulnerability.

1 source
articleCRITICAL 9.1

Critical Vulnerability in GeoVision GV-AS1620: Embedded RSA Private Key Exposure

A critical vulnerability (CVE-2026-18753) with a CVSS score of 9.1 has been discovered in GeoVision's GV-AS1620 (AS-Manager) product. The vulnerability involves an embedded, static RSA private key used for TLS termination by the Lighttpd web server. Exposure of this private key could allow malicious actors to breach the confidentiality and integrity of HTTPS communications. The affected version is V2.07, and a patched version (V2.08) is available. Immediate patching is highly recommended.

1 source
blogHIGH 8.2

Understanding the OnGres SCRAM Silent Channel-Binding Authentication Downgrade Vulnerability

A flaw in the OnGres SCRAM library allows an attacker to silently downgrade a connection from SCRAM-SHA-256-PLUS (with channel binding) to standard SCRAM-SHA-256 (without channel binding), bypassing strict client-side enforcement policies. This vulnerability has a CVSS score of 8.2 and is tracked under CVE-2026-53712.

1 source