CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 26 of 30
- CVE-2025-66001HIGHCVSS 8.8EG 8.82026-01-08
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the sy…
- CVE-2025-66491MEDIUMCVSS 5.9EG 5.92025-12-09
Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backe…
- CVE-2025-66614CRITICALCVSS 9.1EG 9.12026-02-17
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but…
- CVE-2025-67229CRITICALCVSS 9.8EG 9.82026-01-23
An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
- CVE-2025-67601MEDIUMCVSS 4.8EG 4.82026-02-25
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting …
- CVE-2025-67752HIGHCVSS 8.1EG 8.12026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default …
- CVE-2025-68121CRITICALCVSS 10.0EG 10.02026-02-05
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may h…
- CVE-2025-68161MEDIUMCVSS 4.8EG 4.82025-12-18
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html…
- CVE-2025-68482MEDIUMCVSS 5.9EG 6.92026-03-10
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager …
- CVE-2025-69412LOWCVSS 3.4EG 3.42026-01-01
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default…
- CVE-2025-70029HIGHCVSS 7.5EG 7.52026-02-11
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options
- CVE-2025-70043CRITICALCVSS 9.1EG 9.12026-02-23
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options
- CVE-2025-70044MEDIUMCVSS 6.5EG 6.52026-02-23
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
- CVE-2025-70045HIGHCVSS 7.4EG 7.42026-02-23
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSec…
- CVE-2025-70058HIGHCVSS 7.4EG 7.42026-02-23
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios …
- CVE-2025-7095MEDIUMCVSS 6.1EG 6.12025-07-06
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible …
- CVE-2025-71063HIGHCVSS 7.5EG 8.22026-01-12
Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.
- CVE-2025-71261HIGHCVSS 8.6EG 8.62026-06-16
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.
- CVE-2025-7390CRITICALCVSS 9.1EG 9.12025-08-21
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
- CVE-2025-7395CRITICALCVSS 9.2EG 9.22025-07-18
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allow…
- CVE-2025-8393HIGHCVSS 7.3EG 7.32025-08-08
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted…
- CVE-2025-8476HIGHCVSS 8.0EG 8.02025-08-01
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to explo…
- CVE-2025-9293HIGHCVSS 8.1EG 8.12026-02-13
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or mod…
- CVE-2025-9708MEDIUMCVSS 6.8EG 6.82025-09-16
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a maliciou…
- CVE-2025-9785HIGHCVSS 7.7EG 7.72025-09-03
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to …
- CVE-2026-0228LOWCVSS 1.3EG 1.32026-02-11
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.
- CVE-2026-0233HIGHCVSS 8.8EG 8.82026-04-13
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
- CVE-2026-0244HIGHCVSS 8.1EG 8.12026-05-13
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.
- CVE-2026-0248MEDIUMCVSS 5.9EG 5.92026-05-13
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain i…
- CVE-2026-0249MEDIUMCVSS 6.5EG 6.52026-05-13
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administ…
- CVE-2026-0277MEDIUMCVSS 5.9EG 5.92026-07-09
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android an…
- CVE-2026-0872LOWCVSS 2.5EG 2.52026-02-13
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
- CVE-2026-10098MEDIUMCVSS 5.3EG 5.32026-06-25
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup co…
- CVE-2026-10592MEDIUMCVSS 5.3EG 5.32026-06-25
Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.
- CVE-2026-1068MEDIUMCVSS 5.3EG 5.32026-03-11
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
- CVE-2026-11310HIGHCVSS 7.5EG 7.52026-06-25
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verif…
- CVE-2026-11564CRITICALCVSS 9.1EG 9.12026-07-03
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store afte…
- CVE-2026-11999HIGHCVSS 7.5EG 7.52026-06-25
X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application calls X509_verify_cert() with caller-sup…
- CVE-2026-12064HIGHCVSS 7.5EG 7.52026-07-03
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initial…
- CVE-2026-12374MEDIUMCVSS 6.4EG 6.42026-07-01
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root vi…
- CVE-2026-13385CRITICALCVSS 9.5EG 9.52026-07-15
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. …
- CVE-2026-13410HIGHCVSS 8.2EG 8.22026-07-17
Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability betw…
- CVE-2026-1530HIGHCVSS 8.1EG 8.12026-02-02
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive commu…
- CVE-2026-1531HIGHCVSS 8.1EG 8.12026-02-02
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, cap…
- CVE-2026-15683HIGHCVSS 7.5EG 7.52026-07-13
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi…
- CVE-2026-1778MEDIUMCVSS 5.9EG 5.92026-02-02
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed ce…
- CVE-2026-20042MEDIUMCVSS 6.5EG 6.52026-04-01
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exis…
- CVE-2026-20184CRITICALCVSS 9.8EG 9.82026-04-15
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of…
- CVE-2026-21228HIGHCVSS 8.1EG 8.12026-02-10
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
- CVE-2026-21945HIGHCVSS 7.5EG 7.52026-01-20
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →