CVE-2020-11050

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

Scoring

Severity
CRITICAL
CVSS base score
9
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS probability
0.19%
CWE
CWE-297
Published
2020-05-07
Last modified
2026-03-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs