VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 75 of 80
  • CVE-2016-9015LowJan 11, 2017
    risk 0.17cvss 3.7epss 0.01

    Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information…

  • CVE-2026-24508LowMar 11, 2026
    risk 0.16cvss 2.5epss 0.00

    Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2026-0872LowFeb 13, 2026
    risk 0.16cvss —epss 0.00

    Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.

  • CVE-2026-54548LowAug 26, 2026
    risk 0.14cvss 3.3epss 0.00

    kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user-specific SSH configuration exists and adds a global Host * rule containing StrictHostKeyChecking no. In…

  • CVE-2022-23649LowFeb 18, 2022
    risk 0.14cvss 3.3epss 0.00

    Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to version 1.5.2, Cosign can be manipulated to claim that an entry for a signature exists in the Rekor transparency log even if it doesn't. This requires the attacker…

  • CVE-2026-39388LowApr 21, 2026
    risk 0.13cvss 3.1epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate…

  • CVE-2024-29733LowApr 21, 2024
    risk 0.11cvss 2.7epss 0.01

    Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing…

  • CVE-2026-22250LowJan 12, 2026
    risk 0.09cvss 2.5epss 0.00

    wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

  • CVE-2026-0228LowFeb 11, 2026
    risk 0.08cvss —epss 0.00

    An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

  • CVE-2026-93601LowSep 18, 2026
    risk 0.07cvss 2.2epss 0.00

    rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name constraint of accept.example.com was…

  • CVE-2026-93600LowSep 18, 2026
    risk 0.07cvss 2.2epss 0.00

    rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Because name constraints are restrictions on…

  • CVE-2026-63650LowAug 14, 2026
    risk 0.06cvss —epss 0.00

    OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

  • CVE-2002-0862Oct 4, 2002
    risk 0.04cvss —epss 0.16

    The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly…

  • CVE-2012-5783Nov 4, 2012
    risk 0.01cvss —epss 0.09

    Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows…

  • CVE-2026-18257MedJul 29, 2026
    risk 0.00cvss 5.6epss 0.00

    Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted

  • CVE-2026-16107MedJul 28, 2026
    risk 0.00cvss 5.9epss 0.00

    IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-54342HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct…

  • CVE-2026-48021CriJul 24, 2026
    risk 0.00cvss 9.1epss 0.00

    In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions,…

  • CVE-2026-60648HigJul 21, 2026
    risk 0.00cvss 8.0epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-13385CriJul 15, 2026
    risk 0.00cvss —epss 0.00

    An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for…