Description
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.
Published: 2026-08-19
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Armeria xDS before version 1.41.0 causes the TLS peer verification for upstream connections to be silently disabled. As a result, an attacker can intercept or modify traffic between the client and the upstream server without the client detecting a certificate mismatch. This allows a full man‑in‑the‑middle attack, compromising confidentiality, integrity, and authenticity of data exchanged over the compromised connection.

Affected Systems

The vendor LY Corporation’s Armeria library is affected. All releases older than 1.41.0 that include the xDS component are vulnerable. No other product variants or versions are listed as impacted.

Risk and Exploitability

The CVSS base score of 9.1 signals critical severity. The issue is network‑based and does not require local privileges, meaning any actor able to reach the xDS gateway can exploit the flaw. While the EPSS score is not published and the vulnerability is not yet listed in the CISA KEV catalog, the combination of a high CVSS and the capability to silence certificate validation indicates a high likelihood of exploitation if an attacker can target the xDS connection.

Generated by OpenCVE AI on August 19, 2026 at 06:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Armeria to version 1.41.0 or later, which restores proper TLS peer verification
  • If upgrade is delayed, configure the application to enforce TLS certificate validation at runtime or disable silent verification settings manually
  • Limit network exposure by restricting xDS traffic to trusted internal networks and monitoring for unexpected certificate changes

Generated by OpenCVE AI on August 19, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Ly Corporation
Ly Corporation armeria
Vendors & Products Ly Corporation
Ly Corporation armeria

Wed, 19 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Armeria xDS Allows Man‑In‑The‑Middle via Silent TLS Peer Verification Disablement
Weaknesses CWE-297

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ly Corporation Armeria
cve-icon MITRE

Status: PUBLISHED

Assigner: LY-Corporation

Published:

Updated: 2026-08-20T15:36:47.943Z

Reserved: 2026-06-09T06:50:05.781Z

Link: CVE-2026-11751

cve-icon Vulnrichment

Updated: 2026-08-20T15:26:48.444Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T02:16:12.530

Modified: 2026-08-28T21:28:17.300

Link: CVE-2026-11751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:45:04Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch