libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000256.json"