{"id":"PYSEC-2026-1220","summary":"Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation","details":"Allegro Tech BigFlow prior to 1.6.0 is vulnerable to Missing SSL Certificate Validation.","aliases":["CVE-2023-25392","GHSA-w6q2-48ch-fj26"],"modified":"2026-07-07T17:47:32.648086909Z","published":"2026-07-07T11:45:18.103732Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25392"},{"type":"WEB","url":"https://github.com/allegro/bigflow/pull/357"},{"type":"WEB","url":"https://github.com/allegro/bigflow/commit/4ce197ff99bd38693dea59ab5e9b781fbcef4276"},{"type":"WEB","url":"https://github.com/allegro/bigflow/commit/7e956661f76907594e8c82e8fb0af76dbea2a0fc"},{"type":"PACKAGE","url":"https://github.com/allegro/bigflow"},{"type":"WEB","url":"https://lutrasecurity.com/en/articles/cve-2023-25392"},{"type":"PACKAGE","url":"https://pypi.org/project/bigflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w6q2-48ch-fj26"}],"affected":[{"package":{"name":"bigflow","ecosystem":"PyPI","purl":"pkg:pypi/bigflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.0"}]}],"versions":["0.1.0","0.1.1","1.0.0","1.0.1","1.0.1.dev1","1.0.2","1.0.2.dev1","1.0.2.dev2","1.0.3","1.0.4","1.0.dev1","1.0.dev10","1.0.dev11","1.0.dev12","1.0.dev13","1.0.dev14","1.0.dev15","1.0.dev16","1.0.dev17","1.0.dev18","1.0.dev19","1.0.dev2","1.0.dev20","1.0.dev21","1.0.dev22","1.0.dev23","1.0.dev24","1.0.dev25","1.0.dev26","1.0.dev27","1.0.dev28","1.0.dev29","1.0.dev3","1.0.dev30","1.0.dev31","1.0.dev32","1.0.dev33","1.0.dev34","1.0.dev35","1.0.dev36","1.0.dev37","1.0.dev38","1.0.dev39","1.0.dev4","1.0.dev41","1.0.dev42","1.0.dev43","1.0.dev44","1.0.dev45","1.0.dev46","1.0.dev47","1.0.dev48","1.0.dev49","1.0.dev5","1.0.dev50","1.0.dev51","1.0.dev52","1.0.dev53","1.0.dev55","1.0.dev56","1.0.dev57","1.0.dev58","1.0.dev59","1.0.dev6","1.0.dev60","1.0.dev61","1.0.dev63","1.0.dev64","1.0.dev65","1.0.dev66","1.0.dev67","1.0.dev68","1.0.dev69","1.0.dev7","1.0.dev70","1.0.dev71","1.0.dev72","1.0.dev73","1.0.dev74","1.0.dev75","1.0.dev76","1.0.dev77","1.0.dev78","1.0.dev79","1.0.dev8","1.0.dev80","1.0.dev81","1.0.dev82","1.0.dev83","1.0.dev84","1.0.dev85","1.0.dev86","1.0.dev87","1.0.dev88","1.0.dev89","1.0.dev9","1.0.dev90","1.0.dev91","1.0b1","1.0b2","1.0b3","1.0b4","1.0b5","1.0b6","1.0rc1","1.1.0","1.1.0a1","1.1.0a2","1.1.0a3","1.1.1","1.1.2","1.1.3","1.1.4","1.1.dev1","1.1.dev2","1.1.dev3","1.1.dev4","1.1.dev5","1.1.dev6","1.1.dev7","1.1.dev8","1.1.dev9","1.2.0","1.2.0b1","1.2.0b2","1.2.0rc1","1.2.1","1.3.0","1.3.0.dev1","1.3.0.dev10","1.3.0.dev2","1.3.0.dev3","1.3.0.dev4","1.3.0.dev5","1.3.0.dev6","1.3.0.dev7","1.3.0.dev8","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6.dev1","1.3.6.dev2","1.3.6.dev3","1.3.6.dev4","1.4.0","1.4.0.dev1","1.4.1","1.4.1.dev0","1.4.1.dev2","1.4.1.dev3","1.4.1.dev4","1.4.1.dev5","1.4.1.dev6","1.4.1.dev7","1.4.2","1.4.2.dev1","1.4.2.dev2","1.4.2.dev3","1.4.2.dev4","1.4.2.dev5","1.4.2rc1","1.4.2rc2","1.4.2rc3","1.4.2rc4","1.4.2rc5","1.4.2rc6","1.5.0","1.5.0.dev1","1.5.0.dev2","1.5.1","1.5.1.dev1","1.5.2","1.5.2.dev1","1.5.2.dev2","1.5.3","1.5.3.dev1","1.5.4","1.5.4.dev1","1.5.5.dev1","1.5.5.dev2","1.6.0.dev1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/bigflow/PYSEC-2026-1220.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}