GO · FEBRUARY 2026 · EARLY WARNING

Alist Application Vulnerable to MitM Attacks

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-8JMM-3XWX-W974Severity: HIGH

The Alist application appears to disable TLS certificate verification by default for all outgoing storage driver communications, making it vulnerable to Man-in-the-Middle (MitM) attacks. This could allow decryption, theft, and manipulation of data during storage operations.

What happened

According to the GitHub Security Advisory GHSA-8jmm-3xwx-w974, the Alist application is under investigation for an insecure TLS configuration. It is reported that Alist disables TLS certificate verification by default for all outgoing storage driver communications. This configuration reportedly makes the system vulnerable to Man-in-the-Middle (MitM) attacks, potentially allowing attackers to decrypt, steal, and manipulate all data transmitted during storage operations. This severely compromises the confidentiality and integrity of user data.

To assess your exposure, check if your deployment of Alist has the default TLS configuration. If so, it is recommended to upgrade to a version of Alist that enables TLS certificate verification or apply a patch to enable verification. For more detailed information, consult the primary sources, particularly the GitHub Security Advisory GHSA-8jmm-3xwx-w974.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If alist is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats