CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,453 vulnerabilities with CWE-295
CVE-2026-33753 MEDIUM
Improper Certificate Validation in rfc3161-client
CVSS 6.2
CVE-2026-33810 HIGH
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
CVSS 8.2
CVE-2026-32281 HIGH
Inefficient policy validation in crypto/x509
CVSS 7.5
CVE-2026-34580 HIGH
Botan 3.11.0 Trust Anchor Confusion - Certificate Authentication Bypass
CVSS 7.5
CVE-2026-4740 HIGH
Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation
CVSS 8.2
CVE-2026-32144 HIGH
OCSP designated-responder authorization bypass via missing signature verification
CVSS 7.4
CVE-2026-35389 HIGH
Bulwark Webmail S/MIME signature verification accepted self-signed certificates
CVSS 7.5
CVE-2026-35560 HIGH
Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver
CVSS 7.4
CVE-2026-29140 MEDIUM
SEPPmail Secure Email Gateway - S/MIME Signature Additional Certificate
CVSS 5.3
CVE-2026-25834 MEDIUM
Mbed TLS 3.3.0-3.6.5, 4.0.0 - Algorithm Downgrade
CVSS 6.5
CVE-2026-20042 MEDIUM
Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
CVSS 6.5
CVE-2026-4370 CRITICAL
Improper TLS Client/Server authentication and certificate verification on Database Cluster
CVSS 10.0
CVE-2026-34073 MEDIUM
cryptography has incomplete DNS name constraint enforcement on peer names
CVSS 5.3
CVE-2026-32794 MEDIUM
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
CVSS 4.8
CVE-2026-32884 MEDIUM
Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)
CVSS 5.9
CVE-2026-33896 HIGH
node-forge <1.4.0 Certificate Chain Verification - basicConstraints Bypass
CVSS 7.4
CVE-2026-33542 MEDIUM
Incus does not verify combined fingerprint when downloading images from simplestreams servers
CVSS 4.8
CVE-2026-33248 MEDIUM
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
CVSS 4.2
CVE-2026-33308 MEDIUM
mod_gnutls missing key purpose check in client certificate verification
CVSS 6.8
CVE-2026-4587 LOW
HybridAuth SSL Curl.php certificate validation
CVSS 3.7
CVE-2026-4434 HIGH
Devolutions Server <2026.1 - MITM via Disabled TLS Cert Verification
CVSS 8.1
CVE-2026-30836 CRITICAL
Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
CVSS 10.0
CVE-2026-4396 HIGH
Devolutions Hub Reporting Service <=2025.3.1.1 - MITM
CVSS 8.1
CVE-2026-32293 LOW
GL-iNet Comet (GL-RM1) KVM insufficient certificate validation
CVSS 3.7
CVE-2026-32627 HIGH
cpp-httplib <0.37.2 Proxy Redirects - TLS Verification Bypass
CVSS 8.7
Details
Vulnerabilities 1,453