CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

656 vulnerabilities with CWE-345
CVE-2026-53512 CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
CVE-2026-45337 HIGH
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
CVSS 7.6
CVE-2026-48799 HIGH
Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
CVSS 7.7
CVE-2026-48816 MEDIUM
sigstore-js: Insufficient Verification of Data Authenticity
CVSS 6.5
CVE-2026-50526 HIGH
Microsoft .NET 10.0 - .NET Tampering Vulnerability
CVSS 7.0
CVE-2026-47737 HIGH
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVSS 7.5
CVE-2026-47304 HIGH
Microsoft Visual Studio 2022 version 17.12 - .NET Security Feature Bypass Vulnerability
CVSS 8.1
CVE-2026-45069 CRITICAL
Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
CVSS 9.1
CVE-2026-9561 HIGH
Eclipse Kura < 5.6.1 - Insufficient Verification of Data Authenticity
CVE-2026-11901 MEDIUM
WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler
CVSS 5.3
CVE-2026-55883 HIGH
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
CVE-2026-53961 MEDIUM
Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)
CVSS 6.5
CVE-2026-54783 HIGH
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CVE-2026-54781 HIGH
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CVE-2026-54774 HIGH
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CVE-2026-59930 MEDIUM
Mistune < 3.3.0 TOC Plugin - Predictable Heading ID Collision
CVSS 4.3
CVE-2026-55430 MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
CVSS 5.8
CVE-2026-54764 MEDIUM
ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
CVSS 5.8
CVE-2026-54763 CRITICAL
Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
CVSS 10.0
CVE-2026-58593 HIGH
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
CVSS 7.5
CVE-2026-50195 CRITICAL
containerd: CRI checkpoint import allows local image tag poisoning
CVSS 9.9
CVE-2026-13513 MEDIUM
MyScale MyScaleDB SegmentId.h getCacheKey data authenticity
CVSS 5.0
CVE-2026-13507 MEDIUM
volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity
CVSS 5.0
CVE-2026-13483 LOW
arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity
CVSS 3.1
CVE-2026-9242 MEDIUM
RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request
CVSS 5.3
Details
Vulnerabilities 656