CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
686 vulnerabilities with CWE-347
CVE-2026-34872
CRITICAL
Mbed TLS 3.5.x-3.6.5 - Improper Input Validation
CVSS 9.1
CVE-2026-34240
HIGH
jose vulnerable to untrusted JWK header key acceptance during signature verification
CVSS 7.5
CVE-2026-34377
HIGH
Zebra V5 Transaction Verification - Consensus Split
CVSS 8.1
CVE-2026-34155
MEDIUM
RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB
CVSS 5.3
CVE-2026-32883
MEDIUM
Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass
CVSS 5.9
CVE-2026-31946
CRITICAL
OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
CVSS 9.8
CVE-2026-33026
CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-32974
HIGH
OpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification Token
CVSS 8.6
CVE-2026-33895
HIGH
Forge has signature forgery in Ed25519 due to missing S > L check
CVSS 7.5
CVE-2026-33894
HIGH
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
CVSS 7.5
CVE-2026-33487
HIGH
goxmldsig has validateSignature Loop Variable Capture Signature Bypass
CVSS 7.5
CVE-2026-20699
MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.3, < 26.4 - Cryptographic Signature Verification Downgrade
CVSS 6.2
CVE-2026-4600
HIGH
jsrsasign <11.1.1 - Improper Verification of Cryptographic Signature
CVSS 7.4
CVE-2026-4115
LOW
PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification
CVSS 3.7
CVE-2026-4541
LOW
janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification
CVSS 2.5
CVE-2026-4478
HIGH
Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
CVSS 8.1
CVE-2026-32294
MEDIUM
JetKVM insufficient firmware verification
CVSS 4.7
CVE-2026-3564
CRITICAL
ScreenConnect Instance Level Cryptographic Material Exposure
CVSS 9.0
CVE-2026-4258
HIGH
sjcl - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2026-27962
CRITICAL
Authlib JWS JWK Header Injection: Signature Verification Bypass
CVSS 9.1
CVE-2026-3562
HIGH
Philips Hue Bridge - Unauthenticated Authentication Bypass via Ed25519 Signature Verification
CVSS 8.8
CVE-2026-32614
HIGH
Go ShangMi Library <0.41.1 - Infinity-Point Forgery
CVSS 7.5
CVE-2026-21002
MEDIUM
Samsung Galaxy Store <4.6.03.8 - Auth Bypass
CVSS 5.5
CVE-2026-20997
CRITICAL
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 9.8
CVE-2026-20989
LOW
Samsung Mobile Devices - Auth Bypass
CVSS 2.4
Details
Vulnerabilities
686