Improper Certificate Validation vulnerability in rustdesk...
Critical severity
Unreviewed
Published
Mar 5, 2026
to the GitHub Advisory Database
•
Updated Mar 25, 2026
Description
Published by the National Vulnerability Database
Mar 5, 2026
Published to the GitHub Advisory Database
Mar 5, 2026
Last updated
Mar 25, 2026
Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).
This issue affects RustDesk Client: through 1.4.5.
References