Man-in-the-Middle Vulnerability in Armeria-xds from Line Corporation
CVE-2026-11751
9.1CRITICAL
What is CVE-2026-11751?
A vulnerability exists in Armeria-xds where TLS peer verification for xDS upstream connections may become silently disabled. This flaw can facilitate man-in-the-middle attacks, jeopardizing the integrity and confidentiality of data exchanged between services managed by xDS. It is crucial for users of affected versions to upgrade to ensure secure connections and protect against potential interception.
Affected Version(s)
Armeria 1.41.0
