PT-2019-10014 · Square+1 · Okhttp+1

CVE-2018-20200

·

Published

2019-04-18

·

Updated

2026-05-18

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OkHttp versions 3.x through 3.12.0
Description: The issue in OkHttp allows man-in-the-middle attackers to bypass certificate pinning. This is achieved by changing SSLContext and boolean values while hooking the application.
Recommendations: For OkHttp versions 3.x through 3.12.0, consider updating to a version where this issue is addressed, if available. As a temporary workaround, restrict modifications to SSLContext to prevent bypassing certificate pinning.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CVE-2018-20200

Affected Products

Debian
Okhttp