CVEFind.com@CveFindComPatch
The post highlights a critical TLS bypass vulnerability in Alist before v3.57.0 and recommends updating to the patched version 3.57.0 to mitigate the risk.
PulsePatch.io@pulsepatchioDisclosure
Alist's insecure TLS configuration (CVE-2026-25160) may allow data interception; no PoC, exploit, or patch is referenced.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-25160 is disclosed as a critical vulnerability in Alist, where TLS certificate verification is disabled by default prior to v3.57.0; no PoC, exploit, or patch details are provided.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑25160, highlighting Alist’s insecure TLS configuration that permits trivial MITM attacks, and directs readers to a link for further details.
CVE@CVEnewDisclosure
CVE‑2026‑25160 is a TLS certificate verification bypass in Alist, fixed in version 3.57.0, requiring an upgrade to mitigate the vulnerability.