PT-2026-90730 · Socket+1 · Socket Firewall+1
CVE-2026-90651
·
Published
2026-09-12
·
Updated
2026-09-22
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Socket Firewall (socketdev/socket-registry-firewall) versions prior to 2.0.0
Description
In registry mode, the software fails to verify upstream TLS certificates by default. When the
api ssl verify and upstream ssl verify configuration keys are omitted from socket.yml, the system sets SOCKET API SSL VERIFY and UPSTREAM SSL VERIFY to 'false'. Consequently, the OpenResty/Lua HTTP client accepts any certificate, including self-signed or untrusted ones, without validating the chain. This allows an attacker capable of intercepting traffic between the firewall and the Socket API or an upstream package registry to use a crafted certificate to modify responses, substitute package content, or alter allow/block decisions. In versions prior to 1.1.334, the generated nginx configuration lacked the lua ssl trusted certificate directive, preventing successful verification even if the settings were enabled without manual patching.Recommendations
Update to version 2.0.0 or later.
For versions between 1.1.334 and 2.0.0, set
api ssl verify: true and upstream ssl verify: true in socket.yml.
For versions prior to 1.1.334, manually patch the generated nginx configuration to include lua ssl trusted certificate and set api ssl verify: true and upstream ssl verify: true in socket.yml.Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socket Firewall
Socket-Registry-Firewall