VYPR

Ada Web Server AWS

by Adacore

CVEs (3)

  • CVE-2025-52494HigSep 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during connection initialization. When a client initiates an HTTPS connection, the server performs the SSL handshake before assigning the…

  • CVE-2024-55581HigFeb 26, 2025
    risk 0.48cvss 7.4epss 0.00

    When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).

  • CVE-2024-37015HigAug 13, 2024
    risk 0.48cvss 7.4epss 0.00

    An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.