# CVE-2020-11050

## Summary

- **CVE ID:** CVE-2020-11050
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-297
- **Published:** May 7, 2020
- **Last Modified:** Mar 14, 2026

## Description

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

## Affected Products

- TooTallNate — Java-WebSocket (<= 1.4.1)

## References

- [CNA](https://github.com/TooTallNate/Java-WebSocket/security/advisories/GHSA-gw55-jm4h-x339)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 41.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._