216.73.216.197

CVE-2025-70058

· Published 23/02/2026 16:29 · Modified 23/02/2026 18:13

Labels: CVE-2025-70058 2026-02-23CVE-2025-70058[email protected]

Essential information

Published
23/02/2026 16:29
Modified
23/02/2026 18:13
Author
Creator
CISA KEV
No
CWE

Description

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ymfe / yapi cpe:2.3:a:ymfe:yapi:1.12.0:*:*:*:*:*:*:*

References