An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
References
| Link | Resource |
|---|---|
| https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4 | Third Party Advisory |
| https://github.com/YMFE | Product |
| https://github.com/YMFE/yapi | Product |
Configurations
History
No history.
Information
Published : 2026-02-23 16:29
Updated : 2026-02-26 20:03
NVD link : CVE-2025-70058
Mitre link : CVE-2025-70058
CVE.ORG link : CVE-2025-70058
JSON object : View
Products Affected
ymfe
- yapi
CWE
CWE-295
Improper Certificate Validation
