VYPR

s2s-proxy

by Temporalio

CVEs (1)

  • CVE-2026-96770CriSep 23, 2026
    risk 0.53cvss epss

    All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the…