Intel

AIKIDO-2025-10570

@aligent/cdk-prerender-fargate is vulnerable to Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 20, 2025

10

Low Risk

This Affects:

JS@aligent/cdk-prerender-fargate
2.3.5 - 2.13.1
Fixed in 2.14.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM) attacks due to the use of an implicitly Application Load Balancer (ALB) configuration that accepts the outdated and insecure TLS v1.0 and v1.1 protocols. An attacker positioned to intercept client traffic could potentially force a downgrade to a weaker protocol version, compromising the confidentiality and integrity of the encrypted data exchange between the client and the server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@aligent/cdk-prerender-fargate is vulnerable to Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') in versions 2.3.5 - 2.13.1.

How to fix this

Upgrade the @aligent/cdk-prerender-fargate library to the patch version.