{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-11751", "assignerOrgId": "657f3255-0560-4aed-82e4-7f579ec6acfb", "state": "PUBLISHED", "assignerShortName": "LY-Corporation", "dateReserved": "2026-06-09T06:50:05.781Z", "datePublished": "2026-08-19T01:19:34.960Z", "dateUpdated": "2026-08-19T01:20:06.238Z" }, "containers": { "cna": { "affected": [ { "vendor": "LY Corporation", "product": "Armeria", "defaultStatus": "affected", "versions": [ { "version": "1.41.0", "status": "unaffected", "versionType": "custom", "lessThan": "*" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-295" } ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections." } ], "references": [ { "url": "https://line.github.io/security-advisory-blog/CVE-2026-11751/" }, { "url": "https://github.com/line/armeria/security/advisories/GHSA-6qfw-3mvj-m6v5" } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", "baseScore": 9.1, "baseSeverity": "CRITICAL" } } ], "providerMetadata": { "orgId": "657f3255-0560-4aed-82e4-7f579ec6acfb", "shortName": "LY-Corporation", "dateUpdated": "2026-08-19T01:20:06.238Z" } } } }