Hey I found this problem while scanning popular github repos with my static analyzer.
Summary
vnt's TLS client verifier defaults to skipping certificate validation, so
every peer-to-peer VPN tunnel started without an explicit --cert-mode
trusts whatever server answers. An on-path attacker becomes the VPN server
and owns all tunneled traffic.
Details
Verified against current main (2026-09-23). vnt-core/src/tls/verifier.rs:136-140:
pub enum CertValidationMode {
#[default]
InsecureSkipVerification,
...
}
The insecure variant maps to a verifier that accepts every certificate and
every handshake signature (verifier.rs:76-89, ServerCertVerified::assertion()
and HandshakeSignatureValid::assertion() unconditionally). Both CLI fallbacks
(args_config.rs:315 and :428) use unwrap_or(CertValidationMode::InsecureSkipVerification),
so plain vnt --server tcp://... with no cert flag runs with verification off
for TLS TCP and WSS transports.
Impact
CWE-295/CWE-1188 default-off verification in a security-marketed VPN:
on-path attacker impersonates the VPN server, reads and injects tunnel
traffic, and attacks the password-derived channel keys from there.
CVSS: 7.0 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
CWE IDs: CWE-295, CWE-1188
Hey I found this problem while scanning popular github repos with my static analyzer.
Summary
vnt's TLS client verifier defaults to skipping certificate validation, so
every peer-to-peer VPN tunnel started without an explicit --cert-mode
trusts whatever server answers. An on-path attacker becomes the VPN server
and owns all tunneled traffic.
Details
Verified against current main (2026-09-23). vnt-core/src/tls/verifier.rs:136-140:
The insecure variant maps to a verifier that accepts every certificate and
every handshake signature (verifier.rs:76-89, ServerCertVerified::assertion()
and HandshakeSignatureValid::assertion() unconditionally). Both CLI fallbacks
(args_config.rs:315 and :428) use unwrap_or(CertValidationMode::InsecureSkipVerification),
so plain
vnt --server tcp://...with no cert flag runs with verification offfor TLS TCP and WSS transports.
Impact
CWE-295/CWE-1188 default-off verification in a security-marketed VPN:
on-path attacker impersonates the VPN server, reads and injects tunnel
traffic, and attacks the password-derived channel keys from there.
CVSS: 7.0 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
CWE IDs: CWE-295, CWE-1188