ASPLes / nopoll

OpenSource WebSocket toolkit
http://www.aspl.es/nopoll
GNU Lesser General Public License v2.1
126 stars 73 forks source link

Certificate hostnames are not validated #25

Open schmidtw opened 7 years ago

schmidtw commented 7 years ago

When connecting to machines over TLS, certificate hostnames are not being validated against the DNS name of the machine. This enables a man-in-the-middle attach vector.