CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 17 of 19
- CVE-2026-46349MEDIUMCVSS 5.3EG 5.32026-06-24
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activitie…
- CVE-2026-48747MEDIUMCVSS 5.3EG 5.32026-06-15
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the reques…
- CVE-2026-41694MEDIUMCVSS 5.3EG 5.32026-06-10
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a dec…
- CVE-2026-47212MEDIUMCVSS 5.3EG 5.32026-05-29
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature…
- CVE-2026-45755MEDIUMCVSS 5.3EG 5.32026-05-28
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC heade…
- CVE-2025-67903MEDIUMCVSS 5.3EG 5.32026-05-27
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
- CVE-2026-44309MEDIUMCVSS 5.3EG 5.32026-05-15
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking t…
- CVE-2026-6966MEDIUMCVSS 5.3EG 5.32026-04-24
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signa…
- CVE-2026-41301MEDIUMCVSS 5.3EG 5.32026-04-21
OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before event signature validation. An unauthenticated remote attack…
- CVE-2026-34155MEDIUMCVSS 5.3EG 5.32026-03-31
RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first…
- CVE-2026-2746MEDIUMCVSS 5.3EG 5.32026-03-04
SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.
- CVE-2026-27445MEDIUMCVSS 5.3EG 5.32026-03-04
SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signature spoofing.
- CVE-2026-24850MEDIUMCVSS 5.3EG 5.32026-01-28
The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-ds…
- CVE-2026-24807MEDIUMCVSS 5.3EG 5.32026-01-27
Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program file…
- CVE-2025-68925MEDIUMCVSS 5.3EG 5.32026-01-13
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.
- CVE-2025-59803MEDIUMCVSS 5.3EG 5.32025-12-11
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content…
- CVE-2025-59288MEDIUMCVSS 5.3EG 5.32025-10-14
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
- CVE-2025-55229MEDIUMCVSS 5.3EG 5.32025-08-21
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-24015MEDIUMCVSS 5.3EG 5.32025-06-03
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts…
- CVE-2024-49394MEDIUMCVSS 5.3EG 5.32024-11-12
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
- CVE-2024-42459MEDIUMCVSS 5.3EG 5.32024-08-02
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
- CVE-2024-41258MEDIUMCVSS 5.3EG 5.32024-07-31
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2024-41254MEDIUMCVSS 5.3EG 5.32024-07-31
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2024-21988MEDIUMCVSS 5.3EG 5.32024-06-14
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
- CVE-2024-34358MEDIUMCVSS 5.3EG 5.32024-05-14
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMA…
- CVE-2024-23680MEDIUMCVSS 5.3EG 5.32024-01-19
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
- CVE-2023-47122MEDIUMCVSS 5.3EG 5.32023-11-10
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor ser…
- CVE-2023-40178MEDIUMCVSS 5.3EG 5.32023-08-23
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could…
- CVE-2023-35373MEDIUMCVSS 5.3EG 5.32023-07-11
Mono Authenticode Validation Spoofing Vulnerability
- CVE-2023-28226MEDIUMCVSS 5.3EG 5.32023-04-11
Windows Enroll Engine Security Feature Bypass Vulnerability
- CVE-2023-28818MEDIUMCVSS 5.3EG 5.32023-03-24
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could…
- CVE-2023-22742MEDIUMCVSS 5.3EG 5.32023-01-20
libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set …
- CVE-2022-46176MEDIUMCVSS 5.3EG 5.32023-01-11
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MI…
- CVE-2020-36563MEDIUMCVSS 5.3EG 5.32022-12-28
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
- CVE-2022-24773MEDIUMCVSS 5.3EG 5.32022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. T…
- CVE-2021-39909MEDIUMCVSS 5.3EG 5.32021-11-05
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a…
- CVE-2021-41831MEDIUMCVSS 5.3EG 5.32021-10-11
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.
- CVE-2018-18689MEDIUMCVSS 5.3EG 5.32021-01-07
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can…
- CVE-2018-18688MEDIUMCVSS 5.3EG 5.32021-01-07
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attack…
- CVE-2020-8133MEDIUMCVSS 5.3EG 5.32020-11-09
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- CVE-2020-28042MEDIUMCVSS 5.3EG 5.32020-11-02
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
- CVE-2020-16922MEDIUMCVSS 5.3EG 5.32020-10-16
<p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario,…
- CVE-2020-15216MEDIUMCVSS 5.3EG 5.32020-09-29
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available…
- CVE-2018-18509MEDIUMCVSS 5.3EG 5.32019-04-26
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse …
- CVE-2018-1000539MEDIUMCVSS 5.3EG 5.32018-06-26
Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This…
- CVE-2018-10470MEDIUMCVSS 5.3EG 5.32018-06-12
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker can maliciously cr…
- CVE-2018-6459MEDIUMCVSS 5.3EG 5.32018-02-20
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parame…
- CVE-2017-8177MEDIUMCVSS 5.3EG 5.32017-11-22
Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability to hijack the APK and upload modified APK file. Successful exploit could lead to the APP i…
- CVE-2026-97732MEDIUMCVSS 5.1EG 5.12026-09-25
IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G…
- CVE-2025-33069MEDIUMCVSS 5.1EG 5.12025-06-10
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →