libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
{ "versions": [ { "introduced": "2.3.0" }, { "fixed": "3.9.0" }, { "introduced": "0" }, { "last_affected": "9.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000256.json"