VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 15 of 76
  • CVE-2026-32627HigMar 16, 2026
    risk 0.50cvss 8.7epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently…

  • CVE-2022-40620HigJan 28, 2026
    risk 0.50cvss 7.7epss 0.00

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update…

  • CVE-2025-66001HigJan 8, 2026
    risk 0.50cvss 8.8epss 0.00

    NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

  • CVE-2025-14022HigDec 15, 2025
    risk 0.50cvss 7.7epss 0.00

    LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a…

  • CVE-2025-9785HigSep 3, 2025
    risk 0.50cvss epss 0.00

    PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the…

  • CVE-2025-54607HigAug 6, 2025
    risk 0.50cvss 7.7epss 0.00

    Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-48915HigOct 15, 2024
    risk 0.50cvss epss 0.00

    Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, certificate verification in `lib/agent/certificate.dart` does not occur properly. During the delegation verification in the `_checkDelegation` function, the…

  • CVE-2024-40464HigJul 31, 2024
    risk 0.50cvss 8.8epss 0.01

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

  • CVE-2024-35140HigMay 31, 2024
    risk 0.50cvss 7.7epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.

  • CVE-2021-23162HigNov 18, 2021
    risk 0.50cvss 7.7epss 0.00

    Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior…

  • CVE-2021-37219HigSep 7, 2021
    risk 0.50cvss 8.8epss 0.01

    HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.

  • CVE-2021-22926HigAug 5, 2021
    risk 0.50cvss 7.5epss 0.10

    libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask…

  • CVE-2021-3450HigMar 25, 2021
    risk 0.50cvss 7.4epss 0.18

    The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve…

  • CVE-2019-15604HigFeb 7, 2020
    risk 0.50cvss 7.5epss 0.20

    Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

  • CVE-2019-3814HigMar 27, 2019
    risk 0.50cvss 7.7epss 0.02

    It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

  • CVE-2026-54481HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

  • CVE-2026-18089HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon…

  • CVE-2025-71261HigJun 16, 2026
    risk 0.49cvss 8.6epss 0.00

    An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.

  • CVE-2026-45170HigJun 12, 2026
    risk 0.49cvss epss 0.00

    Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

  • CVE-2026-34580HigApr 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the…