High severity8.1NVD Advisory· Published Mar 13, 2018· Updated Jun 17, 2026
CVE-2018-1000096
CVE-2018-1000096
Description
brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tiny-json-httpnpm | >= 1.0.1, < 7.0.0 | 7.0.0 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-7h42-5vj2-cq39ghsaADVISORY
- github.com/brianleroux/tiny-json-http/pull/15nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000096ghsaADVISORY
- github.com/brianleroux/tiny-json-http/commit/3c1e36d8bef3ef5fd8e4447f816d5ffe2bfc3190ghsaWEB
News mentions
0No linked articles in our index yet.