VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 35 of 41
  • CVE-2026-48747MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(),…

  • CVE-2026-47212MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated…

  • CVE-2026-45755MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST…

  • CVE-2026-46349MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing,…

  • CVE-2026-44309MedMay 15, 2026
    risk 0.27cvss 5.3epss 0.00

    Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying…

  • CVE-2026-41301MedApr 21, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before event signature validation. An unauthenticated remote attacker can send forged direct messages to…

  • CVE-2026-34155MedMar 31, 2026
    risk 0.27cvss 5.3epss 0.00

    RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first few bytes of the payload. Given such a…

  • CVE-2026-24850MedJan 28, 2026
    risk 0.27cvss 5.3epss 0.00

    The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures…

  • CVE-2026-24807MedJan 27, 2026
    risk 0.27cvss epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java. This issue…

  • CVE-2025-68925MedJan 13, 2026
    risk 0.27cvss 5.3epss 0.00

    Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.

  • CVE-2025-59288MedOct 14, 2025
    risk 0.27cvss 5.3epss 0.00

    Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

  • CVE-2025-24015MedJun 3, 2025
    risk 0.27cvss 5.3epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be…

  • CVE-2024-42459MedAug 2, 2024
    risk 0.27cvss 5.3epss 0.00

    In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

  • CVE-2024-34358MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.00

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query…

  • CVE-2023-40178MedAug 23, 2023
    risk 0.27cvss 5.3epss 0.00

    Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could impact the user where they would be…

  • CVE-2020-36563MedDec 28, 2022
    risk 0.27cvss 5.3epss 0.00

    XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

  • CVE-2026-55165medJun 25, 2026
    risk 0.26cvss epss

    <!-- obsidian -->Lemur 1.9.0: JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap;…

  • CVE-2026-2625MedApr 3, 2026
    risk 0.26cvss 4.0epss 0.00

    A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code,…

  • CVE-2025-31335MedMar 28, 2025
    risk 0.26cvss 4.0epss 0.00

    The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

  • CVE-2023-23435MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file