{"id":"CVE-2016-10932","aliases":["GHSA-9xjr-m6f3-v5wm","RUSTSEC-2016-0002"],"url":"https://o3.security/vulnerability/CVE-2016-10932","summary":"HTTPS MitM vulnerability due to lack of hostname verification","details":"An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.","published":"2019-08-26T13:15:10.837Z","modified":"2026-07-08T12:53:28.083643Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"hyper","fixedVersion":"0.9.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2016-0002.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:53:28.083643Z"}}