VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (884)

page 42 of 45
  • CVE-2026-20989LowMar 16, 2026
    risk 0.16cvss 2.4epss 0.00

    Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

  • CVE-2026-6873LowJun 3, 2026
    risk 0.13cvss 3.1epss 0.00

    An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context…

  • CVE-2025-12150LowFeb 27, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…

  • CVE-2024-51744LowNov 4, 2024
    risk 0.13cvss 3.1epss 0.01

    golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors…

  • CVE-2026-4541LowMar 22, 2026
    risk 0.09cvss 2.5epss 0.00

    A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is…

  • CVE-2026-47192LowAug 14, 2026
    risk 0.07cvss —epss 0.00

    kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository…

  • CVE-2026-47191LowAug 14, 2026
    risk 0.07cvss —epss 0.00

    kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked…

  • CVE-2026-1237LowJan 28, 2026
    risk 0.07cvss —epss 0.00

    Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain…

  • CVE-2026-48791LowAug 13, 2026
    risk 0.06cvss 2.0epss 0.00

    sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to…

  • CVE-2025-71402LowAug 1, 2026
    risk 0.06cvss —epss 0.00

    better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the cookie signature…

  • CVE-2026-44104CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

  • CVE-2026-13305MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home…

  • CVE-2026-63237MedJul 29, 2026
    risk 0.00cvss 4.8epss 0.00

    A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.

  • CVE-2026-65616HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

  • CVE-2026-14837HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may…

  • CVE-2026-48021CriJul 24, 2026
    risk 0.00cvss 9.1epss 0.00

    In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions,…

  • CVE-2026-10723MedJul 22, 2026
    risk 0.00cvss 6.8epss 0.00

    BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and…

  • CVE-2026-64623HigJul 20, 2026
    risk 0.00cvss 8.6epss 0.00

    Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to…

  • CVE-2026-49998HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight lookup were keyed only by…

  • CVE-2026-45795MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and…