CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,335 vulnerabilities with CWE-295
CVE-2026-20042 MEDIUM
Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
CVSS 6.5
CVE-2026-4370 CRITICAL
Improper TLS Client/Server authentication and certificate verification on Database Cluster
CVSS 10.0
CVE-2026-34073 MEDIUM
cryptography has incomplete DNS name constraint enforcement on peer names
CVSS 5.3
CVE-2026-32794 MEDIUM
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
CVSS 4.8
CVE-2026-32884 MEDIUM
Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)
CVSS 5.9
CVE-2026-33896 HIGH
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
CVSS 7.4
CVE-2026-33542 MEDIUM
Incus does not verify combined fingerprint when downloading images from simplestreams servers
CVSS 4.8
CVE-2026-33248 MEDIUM
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
CVSS 4.2
CVE-2026-33308 MEDIUM
mod_gnutls missing key purpose check in client certificate verification
CVSS 6.8
CVE-2026-4587 LOW
HybridAuth SSL Curl.php certificate validation
CVSS 3.7
CVE-2026-4434 HIGH
Devolutions Server <2026.1 - MITM via Disabled TLS Cert Verification
CVSS 8.1
CVE-2026-30836 CRITICAL
Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
CVSS 10.0
CVE-2026-4396 HIGH
Devolutions Hub Reporting Service <=2025.3.1.1 - MITM
CVSS 8.1
CVE-2026-32293 LOW
GL-iNet Comet (GL-RM1) KVM insufficient certificate validation
CVSS 3.7
CVE-2026-32627 HIGH
cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy
CVSS 8.7
CVE-2026-31798 MEDIUM
JumpServer <4.10.16-lts - Info Disclosure
CVSS 5.0
CVE-2026-2368 HIGH
Lenovo Filez - Code Injection
CVSS 7.1
CVE-2026-1068 MEDIUM
Lenovo Filez - Info Disclosure
CVSS 5.3
CVE-2026-24508 LOW
Dell AWCC <6.12.24.0 - Info Disclosure
CVSS 2.5
CVE-2026-27221 MEDIUM
Acrobat Reader <25.001.21265 - Auth Bypass
CVSS 5.5
CVE-2026-3822 MEDIUM
Taipower APP - Improper Certificate Validation
CVSS 6.5
CVE-2026-24281 HIGH
Apache ZooKeeper <3.8.6/3.9.5 - Auth Bypass
CVSS 7.4
CVE-2026-30840 HIGH
Wallos <4.6.2 - SSRF
CVSS 8.8
CVE-2026-27138 MEDIUM
Rust - DoS
CVSS 5.9
CVE-2026-27137 HIGH
OpenSSL - Certificate Validation Bypass
CVSS 7.5
Details
Vulnerabilities 1,335