TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Checked 2026-10-04 at 01:14 UTC. The most recent advisory here was published 2021-04-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.