Man-in-the-Middle Vulnerability in Armeria-xds from Line Corporation
CVE-2026-11751

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-11751?

A vulnerability exists in Armeria-xds where TLS peer verification for xDS upstream connections may become silently disabled. This flaw can facilitate man-in-the-middle attacks, jeopardizing the integrity and confidentiality of data exchanged between services managed by xDS. It is crucial for users of affected versions to upgrade to ensure secure connections and protect against potential interception.

Affected Version(s)

Armeria 1.41.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.