CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,453 vulnerabilities with CWE-295
CVE-2026-42213 MEDIUM
SolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leak
CVE-2026-42225 MEDIUM
GnuTLS backend silently skips certificate chain verification when verify_peer is false
CVSS 5.9
CVE-2026-7821 HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Unauthenticated Improper Certificate Validation
CVSS 7.4
CVE-2026-5787 HIGH
Ivanti Endpoint Manager Mobile < 12.6.1.1, 12.7.0.1, 12.8.0.1 - Unauthenticated Certificate Spoofing
CVSS 8.9
CVE-2026-42011 HIGH
Gnutls: gnutls: security bypass due to incorrect name constraint handling
CVSS 7.4
CVE-2026-40243 MEDIUM
Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation
CVSS 4.8
CVE-2026-6860 MEDIUM
Eclipse Vert.x 4.3.4-4.5.25, 5.0.0-5.0.10 - Improper Certificate Validation
CVSS 5.3
CVE-2026-43869 HIGH
Apache Thrift: TSSLTransportFactory.java hostname verification
CVSS 7.3
CVE-2026-41016 MEDIUM
Apache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP provider
CVSS 5.9
CVE-2026-40974 MEDIUM
Spring Boot <4.0.6 - SSL Hostname Verification Bypass
CVSS 5.0
CVE-2026-40971 MEDIUM
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 5.0
CVE-2026-40970 MEDIUM
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 5.0
CVE-2026-40557 MEDIUM
Apache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connections
CVSS 4.8
CVE-2026-22747 MEDIUM
Unauthorized User Impersonation when Using X.509 Client Certificates
CVSS 6.8
CVE-2026-40944 MEDIUM
Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles
CVE-2026-39388 LOW
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVSS 3.1
CVE-2026-23776 HIGH
Dell PowerProtect Data Domain - Privilege Escalation
CVSS 7.2
CVE-2026-20184 CRITICAL
Cisco Webex Meetings Certificate Validation Vulnerability
CVSS 9.8
CVE-2026-39984 MEDIUM
Sigstore Timestamp Authority has Improper Certificate Validation in verifier
CVSS 5.5
CVE-2026-0233 HIGH
Autonomous Digital Experience Manager: Improper validation of ADEM certificate
CVSS 8.8
CVE-2026-34477 MEDIUM
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
CVSS 5.9
CVE-2026-5501 HIGH
Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
CVSS 8.1
CVE-2026-5263 MEDIUM
URI nameConstraints not enforced in ConfirmNameConstraints()
CVSS 6.5
CVE-2026-5194 CRITICAL
wolfSSL ECDSA Certificate Verification
CVSS 9.1
CVE-2026-35207 MEDIUM
deepinid plugin in dde-control-center is configured to skip TLS certificate verification when downloading avatar from remote server
CVSS 5.4
Details
Vulnerabilities 1,453