The product does not validate, or incorrectly validates, a certificate.
1,453 vulnerabilities with CWE-295
CVE-2026-6900
HIGH
B&R Industrial Automation APROL - Improper Certificate Validation
CVSS 7.4
CVE-2026-8286
HIGH
curl - Wrong STARTTLS Connection Reuse
CVSS 8.1
CVE-2026-12064
HIGH
curl - Proto-Default Skips SSH Verification
CVSS 7.5
CVE-2026-11564
CRITICAL
curl - Native CA Trust Persist
CVSS 9.1
CVE-2026-8480
MEDIUM
Connection possible to the Administration portal with a revoked certificate
CVSS 4.3
CVE-2026-12374
MEDIUM
Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
CVE-2026-48934
MEDIUM
Node.js 22.x < 22.22.3, 24.x < 24.16.0, 26.x < 26.3.0 - TLS Certificate Validation Bypass
CVSS 4.3
CVE-2026-7532
HIGH
iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
CVSS 7.5
CVE-2026-10098
MEDIUM
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
CVSS 5.3
CVE-2026-6731
HIGH
X.509 name constraint bypass via Subject CN treated as a DNS name
CVSS 7.5
CVE-2026-6450
MEDIUM
wolfSSL - CRL Critical Extension Bypass in ParseCRL_Extensions
CVSS 5.3
CVE-2026-55964
MEDIUM
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
CVSS 5.3
CVE-2026-55960
HIGH
Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation
CVSS 7.5
CVE-2026-11310
HIGH
X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
CVSS 7.5
CVE-2026-10592
MEDIUM
wolfSSL - Wildcard DNS SAN Bypasses CA Name-Constraint Checks
CVSS 5.3
CVE-2026-6091
MEDIUM
Partial-chain verification accepts untrusted intermediate as trust anchor
CVSS 6.5
CVE-2026-11999
HIGH
X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
CVSS 7.5
CVE-2026-46734
HIGH
Dell Display And Peripheral Manager - Improper Certificate Validation
CVSS 7.3
CVE-2026-57289
MEDIUM
Jenkins Bitbucket Push And Pull Request Plugin < 3.3.8 - Improper Certificate Validation
CVSS 4.8
CVE-2026-54323
MEDIUM
Daytona: Git credential leak via git clone with TLS verification disabled
CVSS 5.9
CVE-2026-54100
HIGH
Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft
CVSS 8.3
CVE-2026-9697
HIGH
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVSS 7.4
CVE-2026-9259
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-9258
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-45389
HIGH
OCaml-TLS < 2.1.0 - Client Certificate Impersonation via Insufficient KeyUsage Validation
CVSS 7.4
Details
Vulnerabilities
1,453