VYPR

CAS Client

by Jasig

CVEs (1)

  • CVE-2026-15243Jul 24, 2026
    risk 0.00cvss epss 0.00

    Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate…