CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,395 vulnerabilities with CWE-295
CVE-2026-4740 HIGH
Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation
CVSS 8.2
CVE-2026-32144 HIGH
OCSP designated-responder authorization bypass via missing signature verification
CVSS 7.4
CVE-2026-35389 HIGH
Bulwark Webmail S/MIME signature verification accepted self-signed certificates
CVSS 7.5
CVE-2026-35560 HIGH
Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver
CVSS 7.4
CVE-2026-29140 MEDIUM
SEPPmail Secure Email Gateway - S/MIME Signature Additional Certificate
CVSS 5.3
CVE-2026-25834 MEDIUM
Mbed TLS 3.3.0-3.6.5, 4.0.0 - Algorithm Downgrade
CVSS 6.5
CVE-2026-20042 MEDIUM
Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
CVSS 6.5
CVE-2026-4370 CRITICAL
Improper TLS Client/Server authentication and certificate verification on Database Cluster
CVSS 10.0
CVE-2026-34073 MEDIUM
cryptography has incomplete DNS name constraint enforcement on peer names
CVSS 5.3
CVE-2026-32794 MEDIUM
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
CVSS 4.8
CVE-2026-32884 MEDIUM
Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)
CVSS 5.9
CVE-2026-33896 HIGH
node-forge <1.4.0 Certificate Chain Verification - basicConstraints Bypass
CVSS 7.4
CVE-2026-33542 MEDIUM
Incus does not verify combined fingerprint when downloading images from simplestreams servers
CVSS 4.8
CVE-2026-33248 MEDIUM
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
CVSS 4.2
CVE-2026-33308 MEDIUM
mod_gnutls missing key purpose check in client certificate verification
CVSS 6.8
CVE-2026-4587 LOW
HybridAuth SSL Curl.php certificate validation
CVSS 3.7
CVE-2026-4434 HIGH
Devolutions Server <2026.1 - MITM via Disabled TLS Cert Verification
CVSS 8.1
CVE-2026-30836 CRITICAL
Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
CVSS 10.0
CVE-2026-4396 HIGH
Devolutions Hub Reporting Service <=2025.3.1.1 - MITM
CVSS 8.1
CVE-2026-32293 LOW
GL-iNet Comet (GL-RM1) KVM insufficient certificate validation
CVSS 3.7
CVE-2026-32627 HIGH
cpp-httplib <0.37.2 Proxy Redirects - TLS Verification Bypass
CVSS 8.7
CVE-2026-31798 MEDIUM
JumpServer <4.10.16-lts - Info Disclosure
CVSS 5.0
CVE-2026-2368 HIGH
Lenovo Filez - Remote Code Execution via Improper Certificate Validation
CVSS 7.1
CVE-2026-1068 MEDIUM
Lenovo Filez - Improper Certificate Validation
CVSS 5.3
CVE-2026-24508 LOW
Dell AWCC <6.12.24.0 - Info Disclosure
CVSS 2.5
Details
Vulnerabilities 1,395