CVE-2016-20011: Gnome Libgrss

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

Affected products

  • Gnome Libgrss: up to and including 0.7.0

Published 2021-05-25. Last modified 2026-06-17.