SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-11751

CRITICAL · CVSS 9.1 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical vulnerability exists in armeria-xds versions prior to 1.41.0, where the xDS upstream TLS peer verification can be silently disabled, potentially exposing connections to man-in-the-middle attacks. Organizations utilizing affected versions should prioritize patching to safeguard their xDS-managed upstream connections against unauthorized interception and data breaches. Immediate action is essential for those relying on secure communications within their infrastructure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-11751
Severity
CRITICAL
CVSS
9.1
EPSS
0.24%

Original NVD Description

A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.