CVE-2026-4873 - connection reuse ignores TLS requirement
CVE ID :CVE-2026-4873
Published : May 13, 2026, 8:27 a.m. | 2 hours, 39 minutes ago
Description :A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 13, 2026, 8:27 a.m. | 2 hours, 39 minutes ago
Description :A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...