CVE-2017-5887: Starscream Project Starscream
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).
Affected products
- Starscream Project Starscream: up to and including 2.0.3
Published 2017-04-06. Last modified 2026-06-17.