All CosmicBytez Labs articles tagged #TLS, across news, security advisories, how-to guides, and projects.
Apache HttpComponents Client 5.4+ async mode ignores HostnameVerificationPolicy#BUILTIN, enabling MITM attacks against TLS connections in affected applications.
Stop accepting self-signed certificate warnings. Deploy Smallstep's step-ca as a fully automated internal PKI — complete with ACME support, Traefik integration, and browser trust.
A critical TLS hostname verification flaw in Apache Thrift's c_glib bindings allows network-positioned attackers to conduct man-in-the-middle attacks against any service-to-service communication using the affected transport. Fixed in Apache Thrift 0.24.0.
A newly disclosed vulnerability dubbed HollowByte allows unauthenticated attackers to cause a denial-of-service condition on OpenSSL servers by sending a...
A critical vulnerability in Apache Tomcat's FFM/Panama TLS connector silently ignores invalid or malformed CRL configurations, causing the server to...
A critical flaw in the Haskell crypton-x509-validation library allows TLS clients to accept certificates whose Subject Alternative Names fall outside a...
A critical CVSS 9.4 vulnerability disables TLS certificate validation via TrustAllCerts routines and combines this with hard-coded DES symmetric encryption…
Deploy Traefik v3 as a Docker-native reverse proxy with automatic Let's Encrypt TLS, label-based routing, and security middleware — no more port juggling...
Improper certificate validation in Amazon Athena ODBC driver versions prior to 2.1.0.0 allows man-in-the-middle attackers to intercept authentication...
A CVSS 10.0 critical vulnerability in Juju versions 3.2.0–3.6.18 and 4.0–4.0.3 allows unauthenticated attackers to connect directly to the internal Dqlite...
Google activates ML-KEM post-quantum key encapsulation by default in Chrome 134 and announces migration timeline for all Google Cloud TLS connections.
CVE-2026-1642 affects NGINX OSS and Plus when proxying to upstream TLS servers, allowing attackers to inject plaintext data into responses.