{"id":"CVE-2016-2402","description":"OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.","cvssScore":5.9,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssMetrics":[{"version":"3.1","score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":4.3,"vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-295"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2017-01-30","lastModified":"2026-06-17","affectedProducts":[{"vendor":"squareup","product":"okhttp","versionEnd":"\u003c=2.7.3"},{"vendor":"squareup","product":"okhttp3","version":"3.0.0"},{"vendor":"squareup","product":"okhttp3","version":"3.0.0","update":"rc1"},{"vendor":"squareup","product":"okhttp3","version":"3.0.1"},{"vendor":"squareup","product":"okhttp3","version":"3.1.0"},{"vendor":"squareup","product":"okhttp3","version":"3.1.1"}],"totalAffectedProducts":2,"references":[{"url":"https://github.com/square/okhttp","source":"osv","tags":["PACKAGE"]},{"url":"https://koz.io/pinning-cve-2016-2402","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://publicobject.com/2016/02/11/okhttp-certificate-pinning-vulnerability","source":"osv","tags":["WEB"]},{"url":"http://www.openwall.com/lists/oss-security/2016/02/10/8","source":"osv","tags":["WEB"]},{"url":"http://www.openwall.com/lists/oss-security/2016/02/18/7","source":"osv","tags":["WEB"]},{"url":"https://koz.io/pinning-cve-2016-2402/","source":"cve@mitre.org","tags":["Technical Description","Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E","source":"cve@mitre.org"},{"url":"https://publicobject.com/2016/02/11/okhttp-certificate-pinning-vulnerability/","source":"cve@mitre.org","tags":["Vendor Advisory"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: com.squareup.okhttp3:okhttp"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: com.squareup.okhttp3:okhttp). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"withheld","detail":"Has 2 known POC(s) clearing the evidence bar — requires review despite MEDIUM severity"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"squareup","product":"okhttp","isKnown":true,"cpe":"cpe:2.3:a:squareup:okhttp:*:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"squareup","product":"okhttp3","isKnown":false,"cpe":"cpe:2.3:a:squareup:okhttp3:3.0.0:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"com.squareup.okhttp3:okhttp","introduced":"0","fixed":"2.7.4"},{"name":"com.squareup.okhttp3:okhttp","introduced":"3.0.0","fixed":"3.1.2"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"exploits":[{"source":"github-poc","url":"https://github.com/ikoz/cert-pinning-flaw-poc","title":"Simple script for testing CVE-2016-2402 and similar flaws","date":"2016-03-20T18:04:40Z","stars":13},{"source":"github-poc","url":"https://github.com/ikoz/certPinningVulnerableOkHttp","title":"OkHttp sample app vulnerable to CVE-2016-2402","date":"2016-03-30T23:45:06Z","stars":10}],"signals":{"hasPOC":true,"pocCount":2,"pocSources":["github-poc"],"topStars":13,"firstPOCDate":"2016-03-20T18:04:40Z"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.02249,"percentile":0.81935},"ssvc":{"available":false}}