CVE-2024-55581: Adacore Ada Web Server

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).

Affected products

  • Adacore Ada Web Server: version 25.0 only
  • Debian Debian Linux: version 11.0 only

Published 2025-02-26. Last modified 2026-06-17.