CVE-2026-41860
Cloud Foundry Foundation BOSH
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
- CVSS
- 7.1
- EPSS
- 0.07% 0.09% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04