CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2026-56416 MEDIUM
Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVSS 4.8
CVE-2026-16317 MEDIUM
Silent Drop of TLS 1.3 Encrypted Records in s2n-tls
CVSS 6.5
CVE-2026-13385 CRITICAL
Asus Router - Improper Certificate Validation
CVE-2026-9653 HIGH
1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
CVE-2026-8720 HIGH
HMAC-BLAKE2 final discards message when key length exceeds block size
CVSS 7.5
CVE-2026-50021 MEDIUM
pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
CVSS 6.8
CVE-2026-50128 MEDIUM
Mastodon: Spoofing of attribution domains
CVSS 5.3
CVE-2026-48028 MEDIUM
Mastodon: Removal of integrity-protected JSON entries from signed activities
CVSS 6.5
CVE-2026-49230 CRITICAL
Apache APISIX: Authentication bypass in jwe-decrypt
CVSS 9.1
CVE-2026-34182 CRITICAL
CMS AuthEnvelopedData Processing May Accept Forged Messages
CVSS 9.1
CVE-2026-34181 HIGH
PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVSS 7.4
CVE-2026-8597 HIGH
Missing integrity verification in Triton inference handler in Amazon SageMaker Python SDK
CVSS 7.2
CVE-2026-32148 MEDIUM
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVSS 5.9
CVE-2026-40323 HIGH
SP1 V6 Recursion Circuit Row-Count Binding Gap
CVSS 7.5
CVE-2026-32105 HIGH
xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode
CVSS 7.7
CVE-2026-5479 HIGH
wolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag
CVSS 8.1
CVE-2026-5504 MEDIUM
PKCS7 CBC Padding Oracle — Plaintext Recovery
CVSS 5.3
CVE-2026-26928 HIGH
Lack of Dynamic Library Validation in SzafirHost
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-32318 HIGH
Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32317 HIGH
Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32303 HIGH
Cryptomator: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-28498 HIGH
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVSS 7.5
CVE-2026-32600 HIGH
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
CVE-2026-32313 HIGH
xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
Details
Vulnerabilities 171
Exploit Likelihood Medium