-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.neovisionaries:nv-websocket-client | maven | < 2.1 | 2.1 |
The vulnerability fundamentally occurs in two key areas:
These functions would appear in stack traces during SSL handshake and certificate validation phases when an attacker presents a mismatched certificate. The high confidence comes from the CVE's explicit description of missing hostname verification - a security control that would be implemented precisely in these SSL/TLS-handling functions.
Ongoing coverage of React2Shell