CVE-2025-70058

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
Configurations

Configuration 1 (hide)

cpe:2.3:a:ymfe:yapi:1.12.0:*:*:*:*:*:*:*

History

26 Feb 2026, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:ymfe:yapi:1.12.0:*:*:*:*:*:*:*
References () https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4 - () https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4 - Third Party Advisory
References () https://github.com/YMFE - () https://github.com/YMFE - Product
References () https://github.com/YMFE/yapi - () https://github.com/YMFE/yapi - Product
First Time Ymfe
Ymfe yapi

25 Feb 2026, 15:20

Type Values Removed Values Added
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
Summary
  • (es) Un problema relacionado con CWE-295: Validación Incorrecta de Certificados fue descubierto en YMFE yapi v1.12.0. La aplicación deshabilita la validación de certificados TLS/SSL al establecer 'rejectUnauthorized': false en la configuración del agente HTTPS para las solicitudes de Axios.

23 Feb 2026, 16:29

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 16:29

Updated : 2026-02-26 20:03


NVD link : CVE-2025-70058

Mitre link : CVE-2025-70058

CVE.ORG link : CVE-2025-70058


JSON object : View

Products Affected

ymfe

  • yapi
CWE
CWE-295

Improper Certificate Validation