An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
References
| Link | Resource |
|---|---|
| https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4 | Third Party Advisory |
| https://github.com/YMFE | Product |
| https://github.com/YMFE/yapi | Product |
Configurations
History
26 Feb 2026, 20:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ymfe:yapi:1.12.0:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4 - Third Party Advisory | |
| References | () https://github.com/YMFE - Product | |
| References | () https://github.com/YMFE/yapi - Product | |
| First Time |
Ymfe
Ymfe yapi |
25 Feb 2026, 15:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-295 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.4 |
| Summary |
|
23 Feb 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 16:29
Updated : 2026-02-26 20:03
NVD link : CVE-2025-70058
Mitre link : CVE-2025-70058
CVE.ORG link : CVE-2025-70058
JSON object : View
Products Affected
ymfe
- yapi
CWE
CWE-295
Improper Certificate Validation
