CVE-2026-25060CWE-599

OpenList Insecure TLS Default Configuration

High · published February 2, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
15.5
In the wild
Unconfirmed
What it is

⚡ A default setting is leaving your communications wide open! Prior to version 4.1.10, OpenList Frontend disables TLS certificate verification, paving the way for sneaky Man-in-the-Middle (MitM) attacks. 🔥 Think of it like a hotel check-in where the front desk skips verifying your ID. Without checking who you are, anyone could walk in and pretend to be you, accessing your room and stealing your belongings! If an attacker exploits this vulnerability, they could intercept your storage communications completely undetected. This means they can read, alter, or even delete sensitive data, all while masquerading as a secure connection. The consequences could be catastrophic, leading to data theft and manipulation without raising any alarms!

Put simply

Think of it like a hotel check-in where the front desk skips verifying your ID. Without checking who you are, anyone could walk in and pretend to be you, accessing your room and stealing your belongings! This vulnerability in OpenList Frontend allows attackers to bypass TLS certificate verification, enabling Man-in-the-Middle attacks via network-level exploits like ARP spoofing or rogue access points. As a result, encrypted connections could unknowingly be established with attacker-controlled servers.

What to do

If an attacker exploits this vulnerability, they could intercept your storage communications completely undetected. This means they can read, alter, or even delete sensitive data, all while masquerading as a secure connection. The consequences could be catastrophic, leading to data theft and manipulation without raising any alarms! To secure your system, update OpenList Frontend to version 4.1.10 immediately to restore proper TLS certificate verification settings. Additionally, review your network configurations to identify any potential weak points that could be exploited. 🔒 You've got this! Follow the action items and you’ll be one step closer to securing your system. 🛡️

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00243 · 15.5th percentile
Weakness
CWE-599 · Missing Validation of OpenSSL Certificate
Published
2026-02-02T22:26Z
EPSS history
Timeline
  • 02 FEB 22:26Z
    OpenList Insecure TLS Default Configuration
    cvelistv5