CVE-2015-2674: Restkit

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.

Affected products

  • Restkit Restkit: affected versions not specified

Published 2017-08-09. Last modified 2026-06-17.