CVE-2024-41253: Goframe
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.
Affected products
- Goframe Goframe: version 2.7.2 only
Published 2024-07-31. Last modified 2026-06-17.