CWE-1428Base

Reliance on HTTP instead of HTTPS

Incomplete in the CWE catalog · 2 CVEs mapped

2
CVEs mapped
7.3
Median CVSS
What it is

The product provides or relies on use of HTTP communications when HTTPS is available.

Recent examples
7.0cvss
CVE-2026-10763

PROMOD V is using insecure HTTP communication instead of HTTPS

PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.

HIGHno explanation yet
0%
epss
7.7cvss
CVE-2026-40677

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary…

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1428
Abstraction
Base
Structure
Simple
Status
Incomplete
References (9)