CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 19 of 33
- CVE-2026-92868MEDIUMCVSS 6.5EG 6.52026-09-30
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
- CVE-2026-89102MEDIUMCVSS 6.5EG 6.52026-09-27
In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_S…
- CVE-2026-89135MEDIUMCVSS 6.5EG 6.52026-09-27
A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.…
- CVE-2026-81868MEDIUMCVSS 6.5EG 6.52026-09-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCert…
- CVE-2026-82662MEDIUMCVSS 6.5EG 6.52026-08-31
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth c…
- CVE-2026-81034MEDIUMCVSS 6.5EG 6.52026-08-26
Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true unconditionally, directly beneath a comment stat…
- CVE-2026-78323MEDIUMCVSS 6.5EG 6.52026-08-24
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust…
- CVE-2026-53583MEDIUMCVSS 6.5EG 6.52026-08-20
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/…
- CVE-2026-66404MEDIUMCVSS 6.5EG 6.52026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
- CVE-2025-9291MEDIUMCVSS 6.5EG 6.52026-08-03
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud…
- CVE-2026-50302MEDIUMCVSS 6.5EG 6.52026-07-14
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-50149MEDIUMCVSS 6.5EG 6.52026-07-02
Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.vir…
- CVE-2026-6091MEDIUMCVSS 6.5EG 6.52026-06-25
Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that ends at an intermediate they control and ha…
- CVE-2025-2669MEDIUMCVSS 6.5EG 6.52026-06-22
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token va…
- CVE-2024-47477MEDIUMCVSS 6.5EG 6.52026-06-17
Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with …
- CVE-2026-44213MEDIUMCVSS 6.5EG 6.52026-05-26
The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana bac…
- CVE-2025-32745MEDIUMCVSS 6.5EG 6.52026-05-26
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tamperin…
- CVE-2026-0249MEDIUMCVSS 6.5EG 6.52026-05-13
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administ…
- CVE-2025-42611MEDIUMCVSS 6.5EG 6.52026-05-05
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerab…
- CVE-2026-5263MEDIUMCVSS 6.5EG 6.52026-04-09
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that viola…
- CVE-2026-25834MEDIUMCVSS 6.5EG 6.52026-04-01
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
- CVE-2026-20042MEDIUMCVSS 6.5EG 6.52026-04-01
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exis…
- CVE-2026-3100MEDIUMCVSS 6.5EG 6.52026-02-25
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic…
- CVE-2025-70044MEDIUMCVSS 6.5EG 6.52026-02-23
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
- CVE-2025-32057MEDIUMCVSS 6.5EG 6.52026-01-22
The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the defau…
- CVE-2025-61727MEDIUMCVSS 6.5EG 6.52025-12-03
An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from cl…
- CVE-2025-30669MEDIUMCVSS 6.5EG 6.52025-11-13
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
- CVE-2025-10548MEDIUMCVSS 6.5EG 6.52025-09-23
The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe --insecure, enabling a man-in-…
- CVE-2025-59347MEDIUMCVSS 6.5EG 6.52025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable t…
- CVE-2025-2028MEDIUMCVSS 6.5EG 6.52025-08-06
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
- CVE-2025-35983MEDIUMCVSS 6.5EG 6.52025-07-10
Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Con…
- CVE-2025-48802MEDIUMCVSS 6.5EG 6.52025-07-08
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
- CVE-2025-39205MEDIUMCVSS 6.5EG 6.52025-06-24
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.
- CVE-2025-4947MEDIUMCVSS 6.5EG 6.52025-05-28
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
- CVE-2025-4575MEDIUMCVSS 6.5EG 6.52025-05-22
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it wil…
- CVE-2024-45641MEDIUMCVSS 6.5EG 6.52025-05-20
IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.
- CVE-2023-33861MEDIUMCVSS 6.5EG 6.52025-05-20
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.
- CVE-2025-37730MEDIUMCVSS 6.5EG 6.52025-05-06
Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.
- CVE-2024-23970MEDIUMCVSS 6.5EG 6.52025-01-31
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw ex…
- CVE-2024-8096MEDIUMCVSS 6.5EG 6.52024-09-11
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response…
- CVE-2023-33295MEDIUMCVSS 6.5EG 6.52024-01-19
Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
- CVE-2023-0547MEDIUMCVSS 6.5EG 6.52023-06-02
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects…
- CVE-2023-0430MEDIUMCVSS 6.5EG 6.52023-06-02
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. …
- CVE-2023-1664MEDIUMCVSS 6.5EG 6.52023-05-26
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose …
- CVE-2023-23901MEDIUMCVSS 6.5EG 6.52023-05-10
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdro…
- CVE-2023-30516MEDIUMCVSS 6.5EG 6.52023-04-12
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2…
- CVE-2023-28093MEDIUMCVSS 6.5EG 6.52023-04-10
A user with a compromised configuration can start an unsigned binary as a service.
- CVE-2022-34404MEDIUMCVSS 6.5EG 6.52023-02-11
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denia…
- CVE-2022-45419MEDIUMCVSS 6.5EG 6.52022-12-22
If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem …
- CVE-2022-22747MEDIUMCVSS 6.5EG 6.52022-12-22
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96,…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →