BEAST is a weakness in SSL 3.0 and TLS 1.0 CBC-mode record encryption caused by predictable, chained initialization vectors. A network man-in-the-middle can perform a blockwise chosen-boundary attack against an HTTPS session and iteratively recover encrypted HTTP request-header plaintext. Practical exploitation uses attacker-controlled JavaScript capable of causing chosen requests to the target origin, including through the HTML5 WebSocket, Java URLConnection, or Silverlight WebClient APIs. Affected configurations include vulnerable SSL/TLS implementations and browsers that negotiate SSL 3.0 or TLS 1.0 with CBC cipher suites.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) implementation of the BEAST (Browser Exploit Against SSL/TLS) attack, which targets the vulnerability in SSLv3 and TLS 1.0 when using CBC cipher mode. The main file, BEAST-poc.py, demonstrates the cryptographic process behind the attack, showing how an attacker can recover secret information (such as cookies) from encrypted traffic by exploiting the predictable initialization vector (IV) in these protocols. The PoC simulates the chosen-plaintext attack, where the attacker can control the plaintext sent by the client (e.g., via JavaScript injection) and, by observing the resulting ciphertexts, recover secret data byte by byte. The 'old' directory contains a more complex, earlier version of the PoC, which includes a simulated client, server, and proxy (acting as a MitM), as well as utility modules for AES encryption and terminal output formatting. The exploit is not weaponized but serves as a clear demonstration of the BEAST attack's cryptographic principles. No hardcoded network endpoints or IP addresses are present; the code is designed for local simulation and educational purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BEAST is an SSL confidentiality vulnerability involving CBC encryption with chained initialization vectors. A man-in-the-middle attacker can recover plaintext HTTP headers through a blockwise chosen-boundary attack combined with JavaScript using specified browser APIs. This advisory identifies affected gnutls28 packages and recommends upgrading to version 3.8.9-3+e1 or later. It reports a CVSS v3 base score of 7.5 and available exploits.
The BEAST TLS 1.0/SSL 3.0 attack, referenced in test output showing the evaluated setup is not vulnerable because older protocols are disabled.
The BEAST vulnerability affecting SSL/TLS implementations; the content discusses testing for mitigation status on Windows and OpenSSL.
A medium-severity SSL/TLS CBC-mode vulnerability, known as BEAST, in which chained initialization vectors enable a man-in-the-middle attacker to recover plaintext HTTP headers from an HTTPS session using a blockwise chosen-boundary attack and supporting JavaScript, Java URLConnection, or Silverlight WebClient requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.