CVE Vulnerabilities

CVE-2025-56230

Missing Validation of OpenSSL Certificate

Published: Nov 04, 2025 | Modified: Feb 10, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

Weakness

The product uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements.

Affected Software

NameVendorStart VersionEnd Version
DocsTencent*3.9.20 (including)

Potential Mitigations

References