CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 16 of 19
- CVE-2018-16150MEDIUMCVSS 5.9EG 5.92018-11-07
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the hash value. Consequently, a remote attacker can forge signatures when small public exponents are bein…
- CVE-2018-16149MEDIUMCVSS 5.9EG 5.92018-11-07
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in the ASN.1 structure. Consequently, when small public exponents are being used, a remote attacker can…
- CVE-2018-0501MEDIUMCVSS 5.9EG 5.92018-08-21
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.
- CVE-2018-4111MEDIUMCVSS 5.9EG 5.92018-04-03
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that refere…
- CVE-2017-15090MEDIUMCVSS 5.9EG 5.92018-01-23
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY use…
- CVE-2026-72861MEDIUMCVSS 5.8EG 5.82026-08-20
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof…
- CVE-2024-45607MEDIUMCVSS 5.8EG 5.82024-09-12
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Co…
- CVE-2025-71422MEDIUMCVSS 5.7EG 5.72026-09-27
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not auth…
- CVE-2023-28806MEDIUMCVSS 5.7EG 5.72024-08-06
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.
- CVE-2023-20135MEDIUMCVSS 5.7EG 5.72023-09-13
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOC…
- CVE-2020-12046MEDIUMCVSS 5.7EG 5.72020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.
- CVE-2026-79970MEDIUMCVSS 5.6EG 5.62026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access could…
- CVE-2025-27498MEDIUMCVSS 5.6EG 5.62025-03-03
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is because in decrypt_inplace in asconcore.rs, tag…
- CVE-2024-1721MEDIUMCVSS 5.6EG 5.62024-05-21
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
- CVE-2026-2625MEDIUMCVSS 5.5EG 5.52026-04-03
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in …
- CVE-2026-21002MEDIUMCVSS 5.5EG 5.52026-03-16
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
- CVE-2025-15469MEDIUMCVSS 5.5EG 5.52026-01-27
Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB w…
- CVE-2025-43521MEDIUMCVSS 5.5EG 5.52025-12-12
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
- CVE-2025-43390MEDIUMCVSS 5.5EG 5.52025-11-04
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
- CVE-2025-43185MEDIUMCVSS 5.5EG 5.52025-07-30
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access protected user data.
- CVE-2024-53267MEDIUMCVSS 5.5EG 5.52024-11-26
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a tran…
- CVE-2024-27247MEDIUMCVSS 5.5EG 5.52024-04-09
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
- CVE-2023-42811MEDIUMCVSS 5.5EG 5.52023-09-22
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even…
- CVE-2023-41764MEDIUMCVSS 5.5EG 5.52023-09-12
Microsoft Office Spoofing Vulnerability
- CVE-2023-28228MEDIUMCVSS 5.5EG 5.52023-04-11
Windows Spoofing Vulnerability
- CVE-2022-42793MEDIUMCVSS 5.5EG 5.52022-11-01
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.
- CVE-2022-36056MEDIUMCVSS 5.5EG 5.52022-09-14
Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully veri…
- CVE-2021-40326MEDIUMCVSS 5.5EG 5.52022-08-29
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature…
- CVE-2021-40045MEDIUMCVSS 5.5EG 5.52022-02-09
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-0152MEDIUMCVSS 5.5EG 5.52021-11-17
Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local …
- CVE-2021-3421MEDIUMCVSS 5.5EG 5.52021-05-19
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest …
- CVE-2020-9226MEDIUMCVSS 5.5EG 5.52020-07-06
HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to …
- CVE-2018-10407MEDIUMCVSS 5.5EG 5.52018-06-13
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will…
- CVE-2026-48758MEDIUMCVSS 5.4EG 5.42026-06-26
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to b…
- CVE-2026-48523MEDIUMCVSS 5.4EG 5.42026-05-28
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against …
- CVE-2024-11696MEDIUMCVSS 5.4EG 5.42024-11-26
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that …
- CVE-2024-37886MEDIUMCVSS 5.4EG 5.42024-06-14
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to…
- CVE-2022-23507MEDIUMCVSS 5.4EG 5.42022-12-15
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the te…
- CVE-2020-12692MEDIUMCVSS 5.4EG 5.42020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an …
- CVE-2026-103329MEDIUMCVSS 5.3EG 5.32026-10-09
The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attack…
- CVE-2026-105161MEDIUMCVSS 5.3EG 5.32026-10-04
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The at…
- CVE-2026-103245MEDIUMCVSS 5.3EG 5.32026-10-01
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with …
- CVE-2026-61855MEDIUMCVSS 5.3EG 5.32026-09-25
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a regist…
- CVE-2026-91814MEDIUMCVSS 5.3EG 5.32026-09-23
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed c…
- CVE-2026-9832MEDIUMCVSS 5.3EG 5.32026-09-19
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_st…
- CVE-2026-86080MEDIUMCVSS 5.3EG 5.32026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow stati…
- CVE-2026-81680MEDIUMCVSS 5.3EG 5.32026-08-27
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to de…
- CVE-2026-12860MEDIUMCVSS 5.3EG 5.32026-08-03
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
- CVE-2026-45795MEDIUMCVSS 5.3EG 5.32026-07-16
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJ…
- CVE-2026-9027MEDIUMCVSS 5.3EG 5.32026-07-09
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function regis…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →