PT-2026-90730 · Socket+1 · Socket Firewall+1

CVE-2026-90651

·

Published

2026-09-12

·

Updated

2026-09-22

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Socket Firewall (socketdev/socket-registry-firewall) versions prior to 2.0.0
Description In registry mode, the software fails to verify upstream TLS certificates by default. When the api ssl verify and upstream ssl verify configuration keys are omitted from socket.yml, the system sets SOCKET API SSL VERIFY and UPSTREAM SSL VERIFY to 'false'. Consequently, the OpenResty/Lua HTTP client accepts any certificate, including self-signed or untrusted ones, without validating the chain. This allows an attacker capable of intercepting traffic between the firewall and the Socket API or an upstream package registry to use a crafted certificate to modify responses, substitute package content, or alter allow/block decisions. In versions prior to 1.1.334, the generated nginx configuration lacked the lua ssl trusted certificate directive, preventing successful verification even if the settings were enabled without manual patching.
Recommendations Update to version 2.0.0 or later. For versions between 1.1.334 and 2.0.0, set api ssl verify: true and upstream ssl verify: true in socket.yml. For versions prior to 1.1.334, manually patch the generated nginx configuration to include lua ssl trusted certificate and set api ssl verify: true and upstream ssl verify: true in socket.yml.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90651

Affected Products

Socket Firewall
Socket-Registry-Firewall