VYPR
Medium severity5.9NVD Advisory· Published Aug 22, 2021· Updated Jun 17, 2026

CVE-2021-39361

CVE-2021-39361

Description

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

Affected products

3
  • GNOME/evolution-rssdescription
  • GNOME Foundation/evolution-rssllm-create2 versions
    <=0.3.96+ 1 more
    • (no CPE)range: <=0.3.96
    • cpe:2.3:a:gnome:evolution-rss:*:*:*:*:*:*:*:*range: <=0.3.96

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.