CVE-2017-5887: Starscream Project Starscream

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).

Affected products

Published 2017-04-06. Last modified 2026-06-17.