{"id":"CVE-2021-29495","details":"Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set \"verifyMode = CVerifyPeer\" as documented.","aliases":["GHSA-9vqv-2jj9-7mqr"],"modified":"2026-07-09T01:30:06.694559Z","published":"2021-05-07T16:15:08.347Z","related":["openSUSE-SU-2022:10095-1","openSUSE-SU-2022:10101-1","openSUSE-SU-2024:12253-1"],"references":[{"type":"ADVISORY","url":"https://github.com/nim-lang/security/security/advisories/GHSA-9vqv-2jj9-7mqr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nim-lang/nim","events":[{"introduced":"0"},{"fixed":"3fb5157ab1b666a5a5c34efde0f357a82d433d04"}],"database_specific":{"cpe":"cpe:2.3:a:nim-lang:nim:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.4.2"}],"source":"CPE_RANGE"}}],"versions":["v1.4.0","v1.0.0","v0.20.0","v0.19.0","v0.18.0","v0.17.2","v0.17.0","v0.16.0","v0.15.2","v0.14.2","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.2","v0.11.0","v0.10.2","v0.9.4","v0.9.2","v0.9.0","v0.8.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29495.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}