CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

651 vulnerabilities with CWE-347
CVE-2026-32974 HIGH
OpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification Token
CVSS 8.6
CVE-2026-33895 HIGH
Forge has signature forgery in Ed25519 due to missing S > L check
CVSS 7.5
CVE-2026-33894 HIGH
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
CVSS 7.5
CVE-2026-33487 HIGH
goxmldsig has validateSignature Loop Variable Capture Signature Bypass
CVSS 7.5
CVE-2026-20699 MEDIUM
macOS <14.8.5 - Info Disclosure
CVSS 6.2
CVE-2026-4600 HIGH
jsrsasign <11.1.1 - Improper Verification of Cryptographic Signature
CVSS 7.4
CVE-2026-4115 LOW
PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification
CVSS 3.7
CVE-2026-4541 LOW
janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification
CVSS 2.5
CVE-2026-4478 HIGH
Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
CVSS 8.1
CVE-2026-32294 MEDIUM
JetKVM insufficient firmware verification
CVSS 4.7
CVE-2026-3564 CRITICAL
ScreenConnect Instance Level Cryptographic Material Exposure
CVSS 9.0
CVE-2026-4258 HIGH
sjcl - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2026-27962 CRITICAL
Authlib JWS JWK Header Injection: Signature Verification Bypass
CVSS 9.1
CVE-2026-3562 HIGH
Philips Hue Bridge - Auth Bypass
CVSS 8.8
CVE-2026-32614 HIGH
Go ShangMi Library <0.41.1 - Infinity-Point Forgery
CVSS 7.5
CVE-2026-21002 MEDIUM
Samsung Galaxy Store <4.6.03.8 - Auth Bypass
CVSS 5.5
CVE-2026-20997 CRITICAL
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 9.8
CVE-2026-20989 LOW
Samsung Mobile Devices - Auth Bypass
CVSS 2.4
CVE-2026-28432 HIGH
Misskey <2026.3.1 - Auth Bypass
CVSS 7.5
CVE-2026-3706 LOW
Dropbear <=2025.89 - Improper Signature Verification
CVSS 3.7
CVE-2026-28802 CRITICAL
Authlib 1.6.5-1.6.6 - Auth Bypass
CVSS 9.8
CVE-2026-29000 CRITICAL
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1
CVE-2026-2746 MEDIUM
SEPPmail Secure Email Gateway <15.0.1 - Info Disclosure
CVSS 5.3
CVE-2026-27445 MEDIUM
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 5.3
CVE-2026-3338 HIGH
AWS-LC <1.69.0 - Auth Bypass
CVSS 7.5
Details
Vulnerabilities 651