VYPR
Moderate severityNVD Advisory· Published Nov 4, 2012· Updated Apr 29, 2026

CVE-2012-5825

CVE-2012-5825

Description

Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python httplib library.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tweepyPyPI
< 3.03.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.