CVE-2012-5825

Executive Summary

Tweepy fails to validate that the server hostname matches the Common Name or subjectAltName in the X.509 certificate, enabling attackers to perform man‑in‑the‑middle attacks by presenting any valid certificate. The flaw stems from Python's httplib usage and can be exploited to spoof SSL connections to Tweepy clients.


Authoritative CVE Metadata - CVSS Base Score: 7.4 (HIGH) - Published: 2012-11-04T22:55:04.997 - Last Modified: 2026-09-17T14:22:42.537

Original Description: Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python httplib library.

"Adversity has the effect of eliciting talents, which in prosperous circumstances would have lain dormant."

— Horace
Source: NVD