An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
{
"github_reviewed": true,
"cwe_ids": [
"CWE-295"
],
"github_reviewed_at": "2026-02-25T22:46:40Z",
"nvd_published_at": "2026-02-23T16:29:36Z",
"severity": "HIGH"
}