CVE-2026-35207
Received
Received - Intake
TLS Verification Bypass in dde-control-center plugin-deepinid Enables MITM Attack
Publication date: 2026-04-09
Last updated on: 2026-04-09
Assigner: GitHub, Inc.
Description
Description
dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from openapi.deepin.com or other providers. An MITM attacker could intercept the traffic, replace the avatar with a malicious or misleading image, and potentially identify the user by the avatar. This vulnerability is fixed in dde-control-center 6.1.80 and 5.9.9.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| deepin | dde-control-center | to 6.1.80 (inc) |
| deepin | plugin-deepinid | to 6.1.80 (exc) |
| deepin | dde-control-center | 5.9.9 |
| linuxdeepin | dde_control_center | 6.1.80 |
| linuxdeepin | dde_control_center | 5.9.9 |
| linuxdeepin | deepinid_plugin | From 2.0.1 (inc) to 2.0.9 (inc) |
| linuxdeepin | dde_control_center | From 6.1.35 (inc) to 6.1.80 (exc) |
| linuxdeepin | dde_control_center | From 5.5.3 (inc) to 5.9.9 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |