Impact
A flaw in Armeria xDS before version 1.41.0 causes the TLS peer verification for upstream connections to be silently disabled. As a result, an attacker can intercept or modify traffic between the client and the upstream server without the client detecting a certificate mismatch. This allows a full man‑in‑the‑middle attack, compromising confidentiality, integrity, and authenticity of data exchanged over the compromised connection.
Affected Systems
The vendor LY Corporation’s Armeria library is affected. All releases older than 1.41.0 that include the xDS component are vulnerable. No other product variants or versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 9.1 signals critical severity. The issue is network‑based and does not require local privileges, meaning any actor able to reach the xDS gateway can exploit the flaw. While the EPSS score is not published and the vulnerability is not yet listed in the CISA KEV catalog, the combination of a high CVSS and the capability to silence certificate validation indicates a high likelihood of exploitation if an attacker can target the xDS connection.
OpenCVE Enrichment