Descriptions

A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.

Severity

  • CVSSv4.0 Score: 9.1 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)

Affected Versions

  • Armeria-xds versions less than 1.41.0

Fix

  • Armeria-xds should be updated to latest version (>= 1.41.0).

Reference

  • https://www.cve.org/CVERecord?id=CVE-2026-11751
  • https://github.com/line/armeria/security/advisories/GHSA-6qfw-3mvj-m6v5

Updated: