CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,453 vulnerabilities with CWE-295
CVE-2026-6900 HIGH
B&R Industrial Automation APROL - Improper Certificate Validation
CVSS 7.4
CVE-2026-8286 HIGH
curl - Wrong STARTTLS Connection Reuse
CVSS 8.1
CVE-2026-12064 HIGH
curl - Proto-Default Skips SSH Verification
CVSS 7.5
CVE-2026-11564 CRITICAL
curl - Native CA Trust Persist
CVSS 9.1
CVE-2026-8480 MEDIUM
Connection possible to the Administration portal with a revoked certificate
CVSS 4.3
CVE-2026-12374 MEDIUM
Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
CVE-2026-48934 MEDIUM
Node.js 22.x < 22.22.3, 24.x < 24.16.0, 26.x < 26.3.0 - TLS Certificate Validation Bypass
CVSS 4.3
CVE-2026-7532 HIGH
iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
CVSS 7.5
CVE-2026-10098 MEDIUM
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
CVSS 5.3
CVE-2026-6731 HIGH
X.509 name constraint bypass via Subject CN treated as a DNS name
CVSS 7.5
CVE-2026-6450 MEDIUM
wolfSSL - CRL Critical Extension Bypass in ParseCRL_Extensions
CVSS 5.3
CVE-2026-55964 MEDIUM
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)
CVSS 5.3
CVE-2026-55960 HIGH
Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation
CVSS 7.5
CVE-2026-11310 HIGH
X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
CVSS 7.5
CVE-2026-10592 MEDIUM
wolfSSL - Wildcard DNS SAN Bypasses CA Name-Constraint Checks
CVSS 5.3
CVE-2026-6091 MEDIUM
Partial-chain verification accepts untrusted intermediate as trust anchor
CVSS 6.5
CVE-2026-11999 HIGH
X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
CVSS 7.5
CVE-2026-46734 HIGH
Dell Display And Peripheral Manager - Improper Certificate Validation
CVSS 7.3
CVE-2026-57289 MEDIUM
Jenkins Bitbucket Push And Pull Request Plugin < 3.3.8 - Improper Certificate Validation
CVSS 4.8
CVE-2026-54323 MEDIUM
Daytona: Git credential leak via git clone with TLS verification disabled
CVSS 5.9
CVE-2026-54100 HIGH
Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft
CVSS 8.3
CVE-2026-9697 HIGH
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVSS 7.4
CVE-2026-9259 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-9258 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Improper Certificate Validation
CVSS 6.5
CVE-2026-45389 HIGH
OCaml-TLS < 2.1.0 - Client Certificate Impersonation via Insufficient KeyUsage Validation
CVSS 7.4
Details
Vulnerabilities 1,453