{"id":"CVE-2013-2037","aliases":["GHSA-q48q-77qv-cf9p","PYSEC-2014-81"],"url":"https://o3.security/vulnerability/CVE-2013-2037","summary":"httplib2 incorrectly checks SSL certificate","details":"httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.","published":"2014-01-18T21:55:03Z","modified":"2026-04-10T03:42:46.985735Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.01324,"percentile":0.69055,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"httplib2","fixedVersion":"0.10.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602"},{"type":"ADVISORY","url":"http://code.google.com/p/httplib2/issues/detail?id=282"},{"type":"ADVISORY","url":"http://seclists.org/oss-sec/2013/q2/257"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/52179"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1948-1"},{"type":"ARTICLE","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602"},{"type":"ARTICLE","url":"http://seclists.org/oss-sec/2013/q2/257"},{"type":"EVIDENCE","url":"http://code.google.com/p/httplib2/issues/detail?id=282"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/httplib2/+bug/1175272"},{"type":"FIX","url":"https://bugs.launchpad.net/httplib2/+bug/1175272"},{"type":"REPORT","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706602"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:42:46.985735Z"}}