CVE-2020-11050
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.19%
- CWE
- CWE-297
- Published
- 2020-05-07
- Last modified
- 2026-03-14
Affected products
- TooTallNate Java-WebSocket
Weakness type
Related vulnerabilities
- CVE-2021-21385 — Disabled hostname verification and accepting self-signed certificates
- CVE-2025-3501 — Org.keycloak.protocol.services: keycloak hostname verification
- CVE-2018-10936 — A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
- CVE-2022-32153 — Splunk Enterprise lacked TLS host name validation
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python
- CVE-2026-26214 — Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM