CVE-2025-68637
Severity CVSS v4.0:
Pending analysis
Type:
CWE-297
Improper Validation of Certificate with Host Mismatch
Publication date:
07/01/2026
Last modified:
08/01/2026
Description
The Uniffle HTTP client is configured to trust all SSL certificates and<br />
<br />
disables hostname verification by default. This insecure configuration<br />
exposes all REST API communication between the Uniffle CLI/client and the<br />
Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks.<br />
<br />
<br />
This issue affects all versions from before 0.10.0.<br />
<br />
Users are recommended to upgrade to version 0.10.0, which fixes the issue.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



