epa4all-client: TLS Certificate Validation Disabled in Production
High severity
GitHub Reviewed
Published
May 11, 2026
in
oviva-ag/epa4all-client
•
Updated Jun 8, 2026
Description
Published to the GitHub Advisory Database
May 15, 2026
Reviewed
May 15, 2026
Published by the National Vulnerability Database
May 26, 2026
Last updated
Jun 8, 2026
Impact
An attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing),
document content, and credential exchanges.
Patches
#36
Workarounds
Use the library directly instead of the REST wrapper.
Resources
Credits
Machine Spirits (contact@machinespirits.de)
References