CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 29 of 33
- CVE-2026-15937MEDIUMCVSS 5.3EG 5.32026-09-04
Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoint…
- CVE-2026-38974MEDIUMCVSS 5.3EG 5.32026-07-15
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
- CVE-2026-10098MEDIUMCVSS 5.3EG 5.32026-06-25
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup co…
- CVE-2026-6450MEDIUMCVSS 5.3EG 5.32026-06-25
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This only affects builds with CRL support enable…
- CVE-2026-10592MEDIUMCVSS 5.3EG 5.32026-06-25
Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.
- CVE-2026-55964MEDIUMCVSS 5.3EG 5.32026-06-25
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) …
- CVE-2026-42769MEDIUMCVSS 5.3EG 5.32026-06-09
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation …
- CVE-2026-39835MEDIUMCVSS 5.3EG 5.32026-05-22
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these c…
- CVE-2026-44309MEDIUMCVSS 5.3EG 5.32026-05-15
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking t…
- CVE-2026-8367MEDIUMCVSS 5.3EG 5.32026-05-13
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentica…
- CVE-2026-7009MEDIUMCVSS 5.3EG 5.32026-05-13
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.
- CVE-2026-6860MEDIUMCVSS 5.3EG 5.32026-05-06
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com …
- CVE-2026-29140MEDIUMCVSS 5.3EG 5.32026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
- CVE-2026-34073MEDIUMCVSS 5.3EG 5.32026-03-31
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" prese…
- CVE-2026-1068MEDIUMCVSS 5.3EG 5.32026-03-11
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
- CVE-2026-2748MEDIUMCVSS 5.3EG 5.32026-03-04
SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allowing signature spoofing.
- CVE-2025-27377MEDIUMCVSS 5.3EG 5.32026-01-22
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic…
- CVE-2025-14819MEDIUMCVSS 5.3EG 5.32026-01-08
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary…
- CVE-2025-12047MEDIUMCVSS 5.3EG 5.32025-11-12
A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the appl…
- CVE-2025-10699MEDIUMCVSS 5.3EG 5.32025-10-15
A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.
- CVE-2025-33142MEDIUMCVSS 5.3EG 5.32025-08-14
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
- CVE-2025-2183MEDIUMCVSS 5.3EG 5.32025-08-13
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an att…
- CVE-2025-32989MEDIUMCVSS 5.3EG 5.32025-07-10
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certi…
- CVE-2023-50314MEDIUMCVSS 5.3EG 5.32024-08-14
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted author…
- CVE-2023-50315MEDIUMCVSS 5.3EG 5.32024-08-14
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitiv…
- CVE-2024-41258MEDIUMCVSS 5.3EG 5.32024-07-31
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2024-28067MEDIUMCVSS 5.3EG 5.32024-07-09
A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.
- CVE-2024-39312MEDIUMCVSS 5.3EG 5.32024-07-08
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates m…
- CVE-2024-28161MEDIUMCVSS 5.3EG 5.32024-03-06
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
- CVE-2024-0853MEDIUMCVSS 5.3EG 5.32024-02-03
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which…
- CVE-2023-33760MEDIUMCVSS 5.3EG 5.32024-01-25
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
- CVE-2023-1409MEDIUMCVSS 5.3EG 5.32023-08-23
If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validat…
- CVE-2023-33201MEDIUMCVSS 5.3EG 5.32023-07-05
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation …
- CVE-2023-34410MEDIUMCVSS 5.3EG 5.32023-06-05
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
- CVE-2022-48437MEDIUMCVSS 5.3EG 5.32023-04-12
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error…
- CVE-2023-0466MEDIUMCVSS 5.3EG 5.32023-03-28
The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the implementation of the function does not enable the check which allows certificate…
- CVE-2023-0465MEDIUMCVSS 5.3EG 5.32023-03-28
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and …
- CVE-2022-3913MEDIUMCVSS 5.3EG 5.32023-02-01
Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This failure could allow an attacker in a privileged position on the network to provide their own …
- CVE-2022-41316MEDIUMCVSS 5.3EG 5.32022-10-12
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not…
- CVE-2021-29726MEDIUMCVSS 5.3EG 5.32022-05-17
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.
- CVE-2022-1343MEDIUMCVSS 5.3EG 5.32022-05-03
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case wh…
- CVE-2021-44533MEDIUMCVSS 5.3EG 5.32022-02-24
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpr…
- CVE-2021-44532MEDIUMCVSS 5.3EG 5.32022-02-24
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject…
- CVE-2021-1837MEDIUMCVSS 5.3EG 5.32021-09-08
A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be able to alter network traffic.
- CVE-2021-22939MEDIUMCVSS 5.3EG 5.32021-08-16
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
- CVE-2020-36425MEDIUMCVSS 5.3EG 5.32021-07-19
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
- CVE-2020-4791MEDIUMCVSS 5.3EG 5.32021-02-09
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.
- CVE-2021-3285MEDIUMCVSS 5.3EG 5.32021-01-26
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
- CVE-2020-24025MEDIUMCVSS 5.3EG 5.32021-01-11
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
- CVE-2020-3557MEDIUMCVSS 5.3EG 5.32020-10-21
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due t…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →