Loading HuntDB...

GHSA-fw5f-w62r-p5ww

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Related CVEs

Key Information

GHSA ID
GHSA-fw5f-w62r-p5ww
Published
May 17, 2022 3:57 AM
Last Modified
May 17, 2022 3:57 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.