CVE-2025-71063
low-risk
Published 2026-01-12
Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.
Do I need to act?
-
0.02% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.2/10
High
ADJACENT_NETWORK
/ HIGH complexity
Affected Products (1)
Errands
Affected Vendors
References (5)
Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1123738
Issue Tracking
https://github.com/mrvladus/Errands/issues/401
Release Notes
https://github.com/mrvladus/Errands/releases/tag/46.2.10
26
/ 100
low-risk
Severity
21/34 · High
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal