CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2026-34872 CRITICAL
Mbed TLS 3.5.x-3.6.5 - Improper Input Validation
CVSS 9.1
CVE-2026-34240 HIGH
jose vulnerable to untrusted JWK header key acceptance during signature verification
CVSS 7.5
CVE-2026-34377 HIGH
Zebra V5 Transaction Verification - Consensus Split
CVSS 8.1
CVE-2026-34155 MEDIUM
RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB
CVSS 5.3
CVE-2026-32883 MEDIUM
Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation Bypass
CVSS 5.9
CVE-2026-31946 CRITICAL
OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
CVSS 9.8
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-32974 HIGH
OpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification Token
CVSS 8.6
CVE-2026-33895 HIGH
Forge has signature forgery in Ed25519 due to missing S > L check
CVSS 7.5
CVE-2026-33894 HIGH
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
CVSS 7.5
CVE-2026-33487 HIGH
goxmldsig has validateSignature Loop Variable Capture Signature Bypass
CVSS 7.5
CVE-2026-20699 MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.3, < 26.4 - Cryptographic Signature Verification Downgrade
CVSS 6.2
CVE-2026-4600 HIGH
jsrsasign <11.1.1 - Improper Verification of Cryptographic Signature
CVSS 7.4
CVE-2026-4115 LOW
PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification
CVSS 3.7
CVE-2026-4541 LOW
janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification
CVSS 2.5
CVE-2026-4478 HIGH
Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
CVSS 8.1
CVE-2026-32294 MEDIUM
JetKVM insufficient firmware verification
CVSS 4.7
CVE-2026-3564 CRITICAL
ScreenConnect Instance Level Cryptographic Material Exposure
CVSS 9.0
CVE-2026-4258 HIGH
sjcl - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2026-27962 CRITICAL
Authlib JWS JWK Header Injection: Signature Verification Bypass
CVSS 9.1
CVE-2026-3562 HIGH
Philips Hue Bridge - Unauthenticated Authentication Bypass via Ed25519 Signature Verification
CVSS 8.8
CVE-2026-32614 HIGH
Go ShangMi Library <0.41.1 - Infinity-Point Forgery
CVSS 7.5
CVE-2026-21002 MEDIUM
Samsung Galaxy Store <4.6.03.8 - Auth Bypass
CVSS 5.5
CVE-2026-20997 CRITICAL
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 9.8
CVE-2026-20989 LOW
Samsung Mobile Devices - Auth Bypass
CVSS 2.4
Details
Vulnerabilities 686