co.fs2:fs2-io_sjs1_3@3.1-46-1de1e8b vulnerabilities


  • latest version


  • latest non vulnerable version

  • first published

    a year ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the co.fs2:fs2-io_sjs1_3 package.

Vulnerability Vulnerable Version
  • M
Improper Certificate Validation

co.fs2:fs2-io_sjs1_3 is a compositional, streaming I/O library

Affected versions of this package are vulnerable to Improper Certificate Validation in TLSContextPlatform.scala when establishing a server-mode TLSSocket. The parameter requestCert = true is ignored, and the connection proceeds without certificate validation.


This vulnerability is only exploitable when the following conditions are met:

  1. fs2-io is running on Node.js.

  2. The TLSSocket being established is in server-mode.

  3. The default mTLS setting requestCert = false in TLSParameters is changed to true.

How to fix Improper Certificate Validation?

Upgrade co.fs2:fs2-io_sjs1_3 to version 3.2.11 or higher.