Improper Certificate Validation Affecting unleash package, versions <8.0.1-r0


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.19% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-UNLEASH-20542710
  • published7 Oct 2026
  • disclosed31 Aug 2026

Introduced: 31 Aug 2026

CVE-2026-82662  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade Chainguard unleash to version 8.0.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream unleash package and not the unleash package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS Base Scores

version 3.1