CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
743 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 12 of 15
- CVE-2025-43903MEDIUMCVSS 4.3EG 4.32025-04-18
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
- CVE-2025-4658CRITICALCVSS 9.8EG 9.82025-05-13
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in Open…
- CVE-2025-46774HIGHCVSS 7.5EG 7.52025-10-14
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClie…
- CVE-2025-47827CRITICALCVSS 4.6EG 9.0⚠ KEV2025-06-05
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
- CVE-2025-47934HIGHCVSS 8.7EG 8.72025-05-19
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing thes…
- CVE-2025-47949HIGHCVSS 7.5EG 7.52025-05-19
samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed…
- CVE-2025-52550HIGHCVSS 7.2EG 7.22025-09-02
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious fi…
- CVE-2025-52556CRITICALCVSS 9.3EG 9.32025-06-21
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is perfo…
- CVE-2025-52648CRITICALCVSS 9.8EG 9.82026-03-16
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or uninten…
- CVE-2025-54369CRITICALCVSS 9.3EG 9.32025-07-24
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified wh…
- CVE-2025-54419CRITICALCVSS 10.0EG 10.02025-07-28
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. T…
- CVE-2025-54549MEDIUMCVSS 5.9EG 5.92025-10-29
Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO
- CVE-2025-54982CRITICALCVSS 9.6EG 9.62025-08-05
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.
- CVE-2025-55039MEDIUMCVSS 6.5EG 6.52025-10-15
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.cry…
- CVE-2025-55229MEDIUMCVSS 5.3EG 5.32025-08-21
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-55278HIGHCVSS 8.1EG 8.12025-11-05
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentia…
- CVE-2025-55311MEDIUMCVSS 6.5EG 6.52025-12-11
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript int…
- CVE-2025-57801CRITICALCVSS 9.1EG 9.12025-08-22
gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulne…
- CVE-2025-58356HIGHCVSS 8.3EG 8.32025-10-27
Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the libcryptsetup function crypt_activate_by_passhr…
- CVE-2025-59288MEDIUMCVSS 5.3EG 5.32025-10-14
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
- CVE-2025-59334CRITICALCVSS 9.6EG 9.62025-09-16
Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of .linkr manifest files before using their contents, allowing a tampered manifest …
- CVE-2025-59718CRITICALCVSS 9.1EG 9.8⚠ KEV2025-12-09
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7…
- CVE-2025-59719CRITICALCVSS 9.1EG 9.82025-12-09
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authenticatio…
- CVE-2025-59803MEDIUMCVSS 5.3EG 5.32025-12-11
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content…
- CVE-2025-59934CRITICALCVSS 9.4EG 9.42025-09-26
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying th…
- CVE-2025-6198HIGHCVSS 7.2EG 7.22025-09-19
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
- CVE-2025-64186MEDIUMCVSS 6.5EG 6.52025-11-12
Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that may allow incomplete documents to pass validation. This…
- CVE-2025-64456HIGHCVSS 7.8EG 8.42025-11-10
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
- CVE-2025-64740HIGHCVSS 7.8EG 7.82025-11-13
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2025-64786LOWCVSS 3.3EG 3.32025-12-09
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An a…
- CVE-2025-64787LOWCVSS 3.3EG 3.32025-12-09
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An a…
- CVE-2025-65295HIGHCVSS 8.1EG 8.12025-12-10
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to…
- CVE-2025-65945HIGHCVSS 7.5EG 7.52025-12-04
auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific condition…
- CVE-2025-66567CRITICALCVSS 9.1EG 9.12025-12-09
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri…
- CVE-2025-66568CRITICALCVSS 9.1EG 9.12025-12-09
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformati…
- CVE-2025-67903MEDIUMCVSS 5.3EG 5.32026-05-27
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
- CVE-2025-68113MEDIUMCVSS 6.5EG 6.52025-12-16
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind c…
- CVE-2025-68925MEDIUMCVSS 5.3EG 5.32026-01-13
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.
- CVE-2025-68972MEDIUMCVSS 5.9EG 5.92025-12-27
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified messag…
- CVE-2025-7937HIGHCVSS 7.2EG 7.22025-09-19
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.
- CVE-2025-8454CRITICALCVSS 9.8EG 9.82025-08-01
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the up…
- CVE-2025-9485CRITICALCVSS 9.8EG 9.82025-10-04
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token process…
- CVE-2026-0234CRITICALCVSS 9.1EG 9.12026-04-13
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
- CVE-2026-0265HIGHCVSS 8.1EG 8.12026-05-13
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is hig…
- CVE-2026-0750HIGHCVSS 7.5EG 7.52026-01-28
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.
- CVE-2026-10723MEDIUMCVSS 6.8EG 6.82026-07-22
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23…
- CVE-2026-10795HIGHCVSS 8.1EG 8.12026-06-11
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insuffi…
- CVE-2026-11348HIGHCVSS 8.1EG 8.12026-07-07
Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107.
- CVE-2026-11800HIGHCVSS 8.1EG 8.12026-06-25
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can creat…
- CVE-2026-1190LOWCVSS 3.1EG 3.12026-01-26
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationDat…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →