Vulnerability Description
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.
References
- https://github.com/line/armeria/security/advisories/GHSA-6qfw-3mvj-m6v5
- https://line.github.io/security-advisory-blog/CVE-2026-11751/
FAQ
What is CVE-2026-11751?
CVE-2026-11751 is a documented vulnerability. A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed u...
How severe is CVE-2026-11751?
CVSS scoring is not yet available for CVE-2026-11751. Check NVD for updates.
Is there a patch for CVE-2026-11751?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.