top of page
perceptive_background_267k.jpg

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate veri…

Published:

3 februari 2026 om 23:00:00

Alert date:

4 februari 2026 om 21:03:00

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

Alist file list program versions prior to 3.57.0 disable TLS certificate verification by default for outgoing storage driver communications. This vulnerability makes the system susceptible to Man-in-the-Middle attacks, allowing complete decryption, theft, and manipulation of data during storage operations. The issue severely compromises confidentiality and integrity of user data transmitted through storage operations. The vulnerability has been patched in version 3.57.0.

Technical details

Mitigation steps:

Affected products:

Alist

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page