CVE-2020-12637: Zulipchat Zulip Desktop

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.

Affected products

  • Zulipchat Zulip Desktop: from 0.5.10, before 5.2.0 (fixed in 5.2.0)

Published 2020-05-09. Last modified 2026-06-17.