Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-13482

25
FAUCET Score

CVE-2020-13482 describes a man-in-the-middle vulnerability in EM-HTTP-Request 1.1.5, affecting various em-http-request and Fedora projects. The flaw stems from the library's insecure use of eventmachine, specifically its failure to verify the hostname in TLS server certificates. With a CVSS score of 7.4 (High), this vulnerability could allow an unauthenticated attacker to intercept and manipulate communications, leading to high confidentiality and integrity impacts. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected versions should consider mitigation strategies.

Impacted Technologies

VendorProductVersion(s)CPE
1.1.5CPE matchmatch criteria
cpe:2.3:a:em-http-request_project:em-http-request:1.1.5:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.91%
Probability of exploitation in next 30 days
EPSS Percentile
56.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0091 is in the 22nd percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 Operational Tools for RHEL 7Fixed in: rubygem-em-http-request-0:1.1.5-4.el7ost
View patch
rubygemspatch availablevia ghsa
Product: em-http-requestFixed in: 1.1.6

Vendor Advisories (2)

rubygemsGHSA-q27f-v3r6-9v77high

Improper Certificate Validation in EM-HTTP-Request

May 24, 2021
redhatCVE-2020-13482Important

rubygem-em-http-request: missing SSL hostname validation allows MITM

May 24, 2020

References

github.com / igrigorik/em-http-request/issues/339
ExploitIssue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MKYP5TR5NTVVDX5R4HCNNH2OQR7M4X3J
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Z32PUJA6RGBZ3TKSOTGUXZ45662S3MVF
securitylab.github.com / advisories/GHSL-2020-094-igrigorik-em-http-request
ExploitThird Party Advisory