CVE-2020-24393: Tweetstream Project Tweetstream

Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.

TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.

Affected products

Published 2021-02-19. Last modified 2026-06-17.