CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 30 of 33
- CVE-2020-14039MEDIUMCVSS 5.3EG 5.32020-07-17
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification…
- CVE-2016-11076MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
- CVE-2020-2033MEDIUMCVSS 5.3EG 5.32020-06-10
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with …
- CVE-2020-0119MEDIUMCVSS 5.3EG 5.32020-06-10
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional executi…
- CVE-2020-1758MEDIUMCVSS 5.3EG 5.32020-05-15
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
- CVE-2020-7042MEDIUMCVSS 5.3EG 5.32020-02-27
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never …
- CVE-2020-7041MEDIUMCVSS 5.3EG 5.32020-02-27
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
- CVE-2011-2207MEDIUMCVSS 5.3EG 5.32019-11-27
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
- CVE-2019-16179MEDIUMCVSS 5.3EG 5.32019-09-09
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
- CVE-2017-18588MEDIUMCVSS 5.3EG 5.32019-08-26
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
- CVE-2019-11727MEDIUMCVSS 5.3EG 5.32019-07-23
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatu…
- CVE-2019-8337MEDIUMCVSS 5.3EG 5.32019-02-13
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
- CVE-2018-19982MEDIUMCVSS 5.3EG 5.32018-12-09
An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The prerequisite is that …
- CVE-2018-12087MEDIUMCVSS 5.3EG 5.32018-10-03
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
- CVE-2017-2623MEDIUMCVSS 5.3EG 5.32018-07-27
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue i…
- CVE-2017-1000417MEDIUMCVSS 5.3EG 5.32018-01-22
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.
- CVE-2017-8213MEDIUMCVSS 5.3EG 5.32017-11-22
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle …
- CVE-2016-5648MEDIUMCVSS 5.3EG 5.32017-06-08
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.
- CVE-2017-8301MEDIUMCVSS 5.3EG 5.32017-04-27
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptan…
- CVE-2017-5653MEDIUMCVSS 5.3EG 5.32017-04-18
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
- CVE-2023-22943MEDIUMCVSS 4.8EG 5.32023-02-14
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connec…
- CVE-2012-4948MEDIUMCVSS v2 5.3EG 5.32012-11-14
The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof…
- CVE-2026-63336MEDIUMCVSS 5.1EG 5.12026-08-18
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) co…
- CVE-2026-42213MEDIUMCVSS 5.1EG 5.12026-05-08
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor files is resolved by GpplDocumentLinkHand…
- CVE-2023-28807MEDIUMCVSS 5.1EG 5.12024-01-31
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
- CVE-2009-2409MEDIUMCVSS v2 5.1EG 5.12009-07-30
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof…
- CVE-2026-40992MEDIUMCVSS 5.0EG 5.02026-06-11
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions:…
- CVE-2026-40970MEDIUMCVSS 5.0EG 5.02026-04-27
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per ve…
- CVE-2026-31798MEDIUMCVSS 5.0EG 5.02026-03-13
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When JumpServer sends MFA/OTP codes via Cus…
- CVE-2022-22380MEDIUMCVSS 5.0EG 5.02023-10-17
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957.
- CVE-2005-3170MEDIUMCVSS 5.0EG 5.02005-10-06
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into …
- CVE-2014-3394MEDIUMCVSS v2 5.0EG 5.02014-10-10
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certifica…
- CVE-2024-31955MEDIUMCVSS 4.9EG 4.92024-10-15
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area…
- CVE-2017-18918MEDIUMCVSS 4.9EG 4.92020-06-19
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
- CVE-2026-84850MEDIUMCVSS 4.8EG 4.82026-09-15
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connecti…
- CVE-2026-86889MEDIUMCVSS 4.8EG 4.82026-09-14
A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept net…
- CVE-2026-66410MEDIUMCVSS 4.8EG 4.82026-08-10
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.
- CVE-2026-66406MEDIUMCVSS 4.8EG 4.82026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be execu…
- CVE-2026-65325MEDIUMCVSS 4.8EG 4.82026-07-29
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. …
- CVE-2026-57289MEDIUMCVSS 4.8EG 4.82026-06-24
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, …
- CVE-2026-42789MEDIUMCVSS 4.8EG 4.82026-05-27
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/s…
- CVE-2026-40243MEDIUMCVSS 4.8EG 4.82026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable…
- CVE-2025-10539MEDIUMCVSS 4.8EG 4.82026-04-28
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious execut…
- CVE-2026-40557MEDIUMCVSS 4.8EG 4.82026-04-27
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.r…
- CVE-2026-32794MEDIUMCVSS 4.8EG 4.82026-03-30
Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is inte…
- CVE-2026-33542MEDIUMCVSS 4.8EG 4.82026-03-26
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow…
- CVE-2025-67601MEDIUMCVSS 4.8EG 4.82026-02-25
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting …
- CVE-2025-68161MEDIUMCVSS 4.8EG 4.82025-12-18
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html…
- CVE-2025-60022MEDIUMCVSS 4.8EG 4.82025-11-17
Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on and/or tamper with an encr…
- CVE-2025-58781MEDIUMCVSS 4.8EG 4.82025-09-12
WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →