Cleartext Transmission of Sensitive Information Affecting homeassistant package, versions [,2025.5.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-HOMEASSISTANT-17675440
  • published29 Jun 2026
  • disclosed29 Jun 2026
  • creditUnknown

Introduced: 29 Jun 2026

CVE-2026-55844  (opens in a new tab)
CWE-319  (opens in a new tab)

How to fix?

Upgrade homeassistant to version 2025.5.0 or higher.

Overview

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information in the process that handles SSID allowlist checks for internal network connections. An attacker can intercept sensitive information, such as access tokens and sensor data, by connecting the device to an untrusted or insecure Wi-Fi network, causing the app to fallback to the internal URL and transmit data over potentially unsafe channels.

References

CVSS Base Scores

version 4.0
version 3.1