PT-2026-46134 · Bosh · Bosh

CVE-2026-41860

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BOSH versions prior to 282.1.9
Description An issue in BOSH allows a local attacker to perform Man-in-the-Middle (MITM) attacks to steal Basic-auth credentials or redirect UAA token requests. This occurs because the create async endpoint() and send http get request synchronous() functions within the HttpRequestHelper hard-code the OpenSSL::SSL::VERIFY NONE setting, which disables SSL certificate verification for outgoing HTTP requests. An attacker with local network access can intercept traffic between the bosh-monitor and the BOSH director or UAA.
Recommendations Update to version 282.1.9 or later.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41860

Affected Products

Bosh